漏洞描述 CVE-2024-6387 是 OpenSSH 服务器中的一个严重漏洞,影响基于 glibc 的 Linux 系统。攻击者可以利用该漏洞在无需认证的情况下,通过竞态条件远程执行任意代码,获得系统控制权。这个漏洞源于处理超时信号时的不安全操作,最早在 OpenSSH 8.5p1 版本中引入。
相关漏洞推荐 POC CVE-2025-32433: Erlang/OTP SSH - Remote Code Execution POC CVE-2018-16059: WirelessHART Fieldgate SWG70 3.0 - Local File Inclusion POC CVE-2023-48795: OpenSSH Terrapin Attack - Detection POC CVE-2001-1473: Deprecated SSHv1 Protocol Detection POC CVE-2001-1473: Deprecated SSHv1 Protocol Detection POC unrestricted-ssh-access: Unrestricted - SSH Access POC iam-ssh-keys-rotation: SSH Key Rotation - 90-Day Policy POC gcloud-vm-project-ssh-keys-enabled: Block Project-Wide SSH Keys Not Enabled POC ssh-gssapiauthentication-disabled: sshd GSSAPIAuthentication - Disabled POC ssh-hostbasedauth-disabled: Ensure SSH HostbasedAuthentication - Disabled POC privesc-ssh-agent: ssh-agent - Privilege Escalation POC privesc-sshpass: sshpass - Privilege Escalation POC file-disable-ssh-forwarding: Disable SSH Forwarding