Larvitz :fedora: :redhat:<p>Short summary of the <a href="https://burningboard.net/tags/regreSSHion" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>regreSSHion</span></a> vulnerability (CVE-2024-6387)</p><p>It's an unauthenticated remote code execution that works without user interaction. Therefore a rather high security risk for systems running <a href="https://burningboard.net/tags/openssh" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>openssh</span></a>. </p><p>Affected versions (AFAIK): </p><p>Any version older than 4.4p1 and 8.5p1 until 9.8. The first upstream version, containing a fix is 9.8p1. But since distributions often backport security fixes to older versions, a deeper look is necessary.</p><p>Short summary for bigger distributions:</p><p>Debian: Stable, testing and sid are affected. A patch for stable has been released. (<a href="https://security-tracker.debian.org/tracker/CVE-2024-6387" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">security-tracker.debian.org/tr</span><span class="invisible">acker/CVE-2024-6387</span></a>)</p><p>Ubuntu: 22.04, 23.10 and 23.04 are affected. A patch for them has been released. (<a href="https://ubuntu.com/security/notices/USN-6859-1" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">ubuntu.com/security/notices/US</span><span class="invisible">N-6859-1</span></a>)</p><p>Red Hat: RHEL version 6-8 are not affected. RHEL9 is and by now, there isn't a patch available <a href="https://access.redhat.com/security/cve/CVE-2024-6387" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">access.redhat.com/security/cve</span><span class="invisible">/CVE-2024-6387</span></a>)</p><p><a href="https://burningboard.net/tags/linux" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>linux</span></a> <a href="https://burningboard.net/tags/openssh" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>openssh</span></a> <a href="https://burningboard.net/tags/CVE" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CVE</span></a>-2024-6387 <a href="https://burningboard.net/tags/RCE" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>RCE</span></a> <a href="https://burningboard.net/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a> <a href="https://burningboard.net/tags/distributions" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>distributions</span></a></p>