Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

OpenSSH critical vulnerability CVE-2024-6387 #9555

Closed
rgarcia89 opened this issue Jul 2, 2024 · 3 comments
Closed

OpenSSH critical vulnerability CVE-2024-6387 #9555

rgarcia89 opened this issue Jul 2, 2024 · 3 comments
Labels
feature-request Request for a feature or enhancement

Comments

@rgarcia89
Copy link

Update openssh to version 9.8p1 to mitigate CVE-2024-6387 (https://blog.qualys.com/vulnerabilities-threat-research/2024/07/01/regresshion-remote-unauthenticated-code-execution-vulnerability-in-openssh-server)

We are currently on version 8.9p1 https://github.com/microsoft/azurelinux/blob/2.0/SPECS/openssh/openssh.spec#L1

@rgarcia89 rgarcia89 added the feature-request Request for a feature or enhancement label Jul 2, 2024
@jperrin
Copy link
Contributor

jperrin commented Jul 2, 2024

We're aware of it and working on the fix. Our preference is usually to backport rather than major version jumps, but this will be addressed shortly.

@dalehhirt
Copy link
Member

Will this also address CVE-2023-28531?

@jperrin
Copy link
Contributor

jperrin commented Jul 5, 2024

The updated ssh package was published yesterday with our -6 openssh package. We opted to backport the fix rather than rolling forward to the new major version.

@jperrin jperrin closed this as completed Jul 5, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
feature-request Request for a feature or enhancement
Projects
None yet
Development

No branches or pull requests

3 participants