AlmaLinux 2254 Published by

Updated OpenSSH packages are available for AlmaLinux 9:

AlmaLinux OS 9 - CVE-2024-6387: regreSSHion




AlmaLinux OS 9 - CVE-2024-6387: regreSSHion

If you are running an AlmaLinux OS 9 machine, you need to know about a vulnerability in OpenSSH’s server (sshd) in glibc-based Linux systems that was published earlier today, July 1, 2024. It has been assigned the identifier CVE-2024-6387 and named regreSSHion. This vulnerability is exploitable remotely and grants unauthenticated root access.

Security is our top priority at AlmaLinux and we aim to deliver patches to our users as quickly as possible. The openssh patch for CVE-2024-6387 has been released and is available for AlmaLinux OS 9 users. The decision to build the update and push the package to production on our own (without a CentOS Stream/RHEL update) was made by our newly-formed technical steering committee, ALESCo.

We are committed to working upstream and have submitted this patch to CentOS Stream 9 to benefit the whole ecosystem.

AlmaLinux OS 9 - CVE-2024-6387: regreSSHion