CVE-2024-6387
Openssh: regresshion - race condition in ssh allows rce/dos
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- June 27, 2024
- Published Date
- July 01, 2024
- Last Updated
- May 12, 2026
- Vendor
- , Red Hat
- Product
- , Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions, Red Hat Enterprise Linux 9.2 Extended Update Support, Red Hat OpenShift Container Platform 4.13, Red Hat OpenShift Container Platform 4.14, Red Hat OpenShift Container Platform 4.15, Red Hat OpenShift Container Platform 4.16, Red Hat Ceph Storage 5, Red Hat Ceph Storage 6, Red Hat Ceph Storage 7, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8
- Description
- A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.
CVSS Scores
CVSS v3.1
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC Information
- Exploitation
- poc
- Technical Impact
- total
Exploit Status
- Proof of Concept Available
- Yes (added 2024-10-22 04:50:10 UTC) Source
References
Known Exploited Vulnerability Information
| Source | Added Date |
|---|---|
| The Shadowserver (via CIRCL) | 2025-10-28 06:45:31 UTC |
Scanner Integrations
| Scanner | URL | Date Detected |
|---|---|---|
| Nessus | https://www.tenable.com/plugins/nessus/206464 | 2024-09-03 15:23:00 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
AzrDll/CVE-2024-6387
Type: github • Created: 2025-01-20 09:38:40 UTC • Stars: 2
YassDEV221608/CVE-2024-6387_PoC
Type: github • Created: 2025-01-04 00:25:33 UTC • Stars: 12
anhvutuan/CVE-2024-6387-poc-1
Type: github • Created: 2024-10-22 04:50:10 UTC • Stars: 2
identity-threat-labs/CVE-2024-6387-Vulnerability-Checker
Type: github • Created: 2024-08-28 13:28:08 UTC • Stars: 2
l-urk/CVE-2024-6387
Type: github • Created: 2024-07-30 06:13:11 UTC • Stars: 10
prelearn-code/CVE-2024-6387
Type: github • Created: 2024-07-25 02:32:19 UTC • Stars: 2
ThatNotEasy/CVE-2024-6387
Type: github • Created: 2024-07-15 16:04:57 UTC • Stars: 2
filipi86/CVE-2024-6387-Vulnerability-Checker
Type: github • Created: 2024-07-09 17:40:19 UTC • Stars: 96
Karmakstylez/CVE-2024-6387
Type: github • Created: 2024-07-08 11:27:49 UTC • Stars: 99
azurejoga/CVE-2024-6387-how-to-fix
Type: github • Created: 2024-07-05 21:29:11 UTC • Stars: 5
lala-amber/CVE-2024-6387
Type: github • Created: 2024-07-04 13:28:53 UTC • Stars: 3
Symbolexe/CVE-2024-6387
Type: github • Created: 2024-07-03 08:22:57 UTC • Stars: 2
sxlmnwb/CVE-2024-6387
Type: github • Created: 2024-07-03 06:08:32 UTC • Stars: 13
l0n3m4n/CVE-2024-6387
Type: github • Created: 2024-07-02 18:32:46 UTC • Stars: 90
th3gokul/CVE-2024-6387
Type: github • Created: 2024-07-02 17:04:52 UTC • Stars: 5
MrR0b0t19/CVE-2024-6387-Exploit-POC
Type: github • Created: 2024-07-02 16:34:12 UTC • Stars: 3
AiGptCode/ssh_exploiter_CVE-2024-6387
Type: github • Created: 2024-07-02 12:57:35 UTC • Stars: 10
ACHUX21/checker-CVE-2024-6387
Type: github • Created: 2024-07-02 12:48:27 UTC • Stars: 2
devarshishimpi/CVE-2024-6387-Check
Type: github • Created: 2024-07-02 11:55:39 UTC • Stars: 13
PrincipalAnthony/CVE-2024-6387-Updated-x64bit
Type: github • Created: 2024-07-02 09:45:04 UTC • Stars: 3
paradessia/CVE-2024-6387-nmap
Type: github • Created: 2024-07-02 08:19:55 UTC • Stars: 3
d0rb/CVE-2024-6387
Type: github • Created: 2024-07-02 06:53:35 UTC • Stars: 41
thegenetic/CVE-2024-6387-exploit
Type: github • Created: 2024-07-02 04:09:44 UTC • Stars: 14
ahlfors/CVE-2024-6387
Type: github • Created: 2024-07-02 03:42:35 UTC • Stars: 2
TAM-K592/CVE-2024-6387
Type: github • Created: 2024-07-02 02:51:37 UTC • Stars: 10
muyuanlove/CVE-2024-6387fixshell
Type: github • Created: 2024-07-02 02:35:24 UTC • Stars: 2
AiK1d/CVE-2024-6387
Type: github • Created: 2024-07-02 01:08:05 UTC • Stars: 6
bigb0x/CVE-2024-6387
Type: github • Created: 2024-07-01 20:45:53 UTC • Stars: 31
xaitax/CVE-2024-6387_Check
Type: github • Created: 2024-07-01 20:33:20 UTC • Stars: 482
getdrive/CVE-2024-6387-PoC
Type: github • Created: 2024-07-01 12:51:18 UTC • Stars: 23
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Detected by Nessus
-
Proof of Concept Exploit Available
-
Added to KEVIntel