USN-6859-1: OpenSSH vulnerability
sudo apt update && sudo apt upgrade -y
# OpenSSH CVE-2024-6387 has been fixed for 22.04 LTS, 23.10 and 24.04 LTS.
# RegreSSHion: Possible RCE Due To A Race Condition In Signal Handling.
# For more details see: https://ubuntu.com/security/notices/USN-6859-1.
1 July 2024
OpenSSH could be made to bypass authentication and remotely access systems without proper credentials.
Releases
Packages
- openssh - secure shell (SSH) for secure access to remote machines
Details
It was discovered that OpenSSH incorrectly handled signal management. A
remote attacker could use this issue to bypass authentication and remotely
access systems without proper credentials.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 24.04
Ubuntu 23.10
Ubuntu 22.04
In general, a standard system update will make all the necessary changes.