CVE-2024-6409: Red Hat Enterprise Linux 10
High severity, CVSS 7.0. EPSS: 27.9% chance of exploitation in the next 30 days.
A race condition vulnerability was discovered in how signals are handled by OpenSSH's server (sshd). If a remote attacker does not authenticate within a set time period, then sshd's SIGALRM handler is called asynchronously. However, this signal handler calls various functions that are not async-signal-safe, for example, syslog(). As a consequence of a successful attack, in the worst case scenario, an attacker may be able to perform a remote code execution (RCE) as an unprivileged user running the sshd server.
Affected products
- Red Hat Red Hat Enterprise Linux 10
- Red Hat Red Hat Enterprise Linux 6
- Red Hat Red Hat Enterprise Linux 7
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 9: before 0:8.7p1-38.el9_4.4 (fixed in 0:8.7p1-38.el9_4.4)
- Red Hat Red Hat Enterprise Linux 9.0 Update Services For SAP Solutions: before 0:8.7p1-12.el9_0.3 (fixed in 0:8.7p1-12.el9_0.3)
- Red Hat Red Hat Enterprise Linux 9.2 Extended Update Support: before 0:8.7p1-30.el9_2.7 (fixed in 0:8.7p1-30.el9_2.7)
- Red Hat Red Hat Openshift Container Platform 4.13: before 413.92.202408122222-0 (fixed in 413.92.202408122222-0)
- Red Hat Red Hat Openshift Container Platform 4.14: before 414.92.202407300859-0 (fixed in 414.92.202407300859-0)
- Red Hat Red Hat Openshift Container Platform 4.15: before 415.92.202407301159-0 (fixed in 415.92.202407301159-0)
- Red Hat Red Hat Openshift Container Platform 4.16: before 416.94.202407171205-0 (fixed in 416.94.202407171205-0)
Published 2024-07-08. Last modified 2026-08-21.