Database/Kernel, userspace & hypervisor

OpenSSH (sshd): regreSSHion: signal-handler race in sshd giving unauthenticated remote root on glibc Linux
CVSS 8.1CVE-2024-6387Kernel, userspace & hypervisorcurated
Impact
regreSSHion: signal-handler race in sshd giving unauthenticated remote root on glibc Linux
Who can reach it
Unauthenticated network
What to do
Package update + sshd restart; no reboot. Interim mitigation LoginGraceTime 0 (costs DoS resilience). Highest-priority item for any tenant-reachable bastion or management SSH endpoint
References
Related entries
- OpenSSH (sshd): Pre-auth memory/CPU amplification - denial of service against sshdCVE-2025-26466 · OpenSSH (sshd)Medium
- Linux kernel (net/smc): The CLC prefix-match check on the listen path dereferences the destination cache entry'sCVE-2025-40168 · Linux kernel (net/smc)High
- libssh: unchecked OpenSSL error can leave a partially initialized ChaCha20 context in useCVE-2025-5987 · libssh (ChaCha20 cipher context initialization via OpenSSL)High
- OpenSSH scp: file fetched as root with -O and without -p can land setuid or setgidCVE-2026-35385 · OpenSSH scp (legacy SCP protocol mode, -O without -p)High
- Linux SLUB: krealloc __GFP_ZERO guarantee broken when red zoning is enabled without user trackingCVE-2026-64368 · Linux kernel SLUB allocator (init-on-alloc zeroing under SLAB_RED_ZONE)High
- Linux SUNRPC: unchecked percpu_counter_init leaves nfsd running on NULL per-cpu statsCVE-2026-89547 · Linux kernel SUNRPC (__svc_create per-pool percpu_counter init)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.