{"id":"CVE-2024-6409","summary":"Openssh: possible remote code execution due to a race condition in signal handling affecting red hat enterprise linux 9","details":"A race condition vulnerability was discovered in how signals are handled by OpenSSH's server (sshd). If a remote attacker does not authenticate within a set time period, then sshd's SIGALRM handler is called asynchronously. However, this signal handler calls various functions that are not async-signal-safe, for example, syslog(). As a consequence of a successful attack, in the worst case scenario, an attacker may be able to perform a remote code execution (RCE) as an unprivileged user running the sshd server.","modified":"2026-08-23T03:42:54.239018466Z","published":"2024-07-08T17:57:10.517Z","related":["ALSA-2024:4457"],"database_specific":{"cna_assigner":"redhat","cwe_ids":["CWE-364"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/6xxx/CVE-2024-6409.json"},"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2024/07/08/2"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2024/07/09/2"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2024/07/09/5"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2024/07/10/1"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2024/07/10/2"},{"type":"WEB","url":"https://access.redhat.com/downloads/content/package-browser/"},{"type":"WEB","url":"https://catalog.redhat.com/software/containers/"},{"type":"WEB","url":"https://explore.alas.aws.amazon.com/CVE-2024-6409.html"},{"type":"WEB","url":"https://security-tracker.debian.org/tracker/CVE-2024-6409"},{"type":"WEB","url":"https://sig-security.rocky.page/issues/CVE-2024-6409/"},{"type":"WEB","url":"https://ubuntu.com/security/CVE-2024-6409"},{"type":"WEB","url":"https://www.openssh.com/"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-6409.html"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2024:4457"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2024:4613"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2024:4716"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2024:4910"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2024:4955"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2024:4960"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2024:5444"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2024-6409"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/6xxx/CVE-2024-6409.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-6409"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20240712-0003/"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2295085"},{"type":"REPORT","url":"https://bugzilla.suse.com/show_bug.cgi?id=1227217"},{"type":"FIX","url":"https://github.com/openela-main/openssh/commit/c00da7741d42029e49047dd89e266d91dcfbffa0"},{"type":"PACKAGE","url":"https://anongit.mindrot.org/openssh.git"},{"type":"ARTICLE","url":"https://almalinux.org/blog/2024-07-09-cve-2024-6409/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/openela-main/openssh","events":[{"introduced":"0"},{"fixed":"c00da7741d42029e49047dd89e266d91dcfbffa0"}],"database_specific":{"source":"REFERENCES"}}],"versions":["imports/el9/openssh-8.7p1-38.el9_4.1","imports/el9/openssh-8.7p1-38.el9","imports/el9/openssh-8.7p1-34.el9_3.3","imports/el9/openssh-8.7p1-34.el9","imports/el9/openssh-8.7p1-30.el9_2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-6409.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H"}]}