CVE-2024-6387Disclosure(almalinux / 500f)

CRITICALCVSS 8.1 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch almalinux 500f systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.

9.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-364CWE-362

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • 500f
  • 500f_firmware
  • 8300
  • 8300_firmware

Threat summary

  • Active exploitation appears in 3 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 29 mentions across 25 observed days

What's happening

  • Active exploitation reported across 3 signals
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 7 signals
  • Patch or workaround mentioned in 11 signals
  • Technical details provided in 10 signals
  • Disclosure: 9 classified signals
  • General: 6 classified signals
  • Peaked 23d ago at 2 mentions (2026-02-04); latest day: 1
  • 29 total mentions across 25 days

Affected systems

Products
500f500f_firmware83008300_firmware87008700_firmwarea150a150_firmwarea1ka1k_firmware

27 versions affected across 81 products

Deep dive

Activity timeline29 mentions / 25d
01122Mentions · 2026-02-02: 1Mentions · 2026-02-04: 2Mentions · 2026-02-12: 1Mentions · 2026-02-25: 1Mentions · 2026-02-28: 2Mentions · 2026-03-03: 1Mentions · 2026-03-06: 1Mentions · 2026-03-08: 1Mentions · 2026-03-15: 1Mentions · 2026-03-21: 1Mentions · 2026-03-31: 1Mentions · 2026-04-11: 2Mentions · 2026-04-15: 1Mentions · 2026-04-17: 1Mentions · 2026-06-01: 1Mentions · 2026-06-16: 1Mentions · 2026-06-19: 1Mentions · 2026-06-23: 1Mentions · 2026-06-24: 1Mentions · 2026-07-02: 2Mentions · 2026-07-10: 1Mentions · 2026-07-31: 1Mentions · 2026-08-26: 1Mentions · 2026-08-28: 1Mentions · 2026-10-07: 1PoC Mentioned / Linked · 2026-02-25: 1PoC Mentioned / Linked · 2026-02-28: 1PoC Mentioned / Linked · 2026-03-06: 1PoC Mentioned / Linked · 2026-03-08: 1PoC Mentioned / Linked · 2026-03-15: 1PoC Mentioned / Linked · 2026-07-31: 1PoC Mentioned / Linked · 2026-08-28: 1Exploit Tool / Code · 2026-03-15: 1Exploit Tool / Code · 2026-08-28: 1Active Exploitation · 2026-02-02: 1Active Exploitation · 2026-03-31: 1Active Exploitation · 2026-04-17: 1Patch / Workaround · 2026-02-12: 1Patch / Workaround · 2026-02-28: 1Patch / Workaround · 2026-03-03: 1Patch / Workaround · 2026-03-15: 1Patch / Workaround · 2026-04-11: 2Patch / Workaround · 2026-04-17: 1Patch / Workaround · 2026-06-01: 1Patch / Workaround · 2026-07-10: 1Patch / Workaround · 2026-08-26: 1Patch / Workaround · 2026-08-28: 1Technical Details · 2026-02-02: 1Technical Details · 2026-02-04: 1Technical Details · 2026-02-25: 1Technical Details · 2026-02-28: 2Technical Details · 2026-04-15: 1Technical Details · 2026-06-16: 1Technical Details · 2026-06-23: 1Technical Details · 2026-06-24: 1Technical Details · 2026-07-10: 102-0202-1202-2803-0603-1503-3104-1506-0106-1906-2407-1008-2610-07
Signal classification6 categories
Disclosure
932.1%
General
621.4%
Patch
621.4%
Active Exploitation
310.7%
PoC
310.7%
Exploit
13.6%
Referenced assets23 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-021
Active Exploitation1
2026-02-042
General2
2026-02-121
Patch1
2026-02-251
Disclosure1
2026-02-282
Disclosure1Patch1
2026-03-031
Disclosure1
2026-03-061
PoC1
2026-03-081
PoC1
2026-03-151
Exploit1
2026-03-211
General1
2026-03-311
Active Exploitation1
2026-04-112
Patch2
2026-04-151
Disclosure1
2026-04-171
Active Exploitation1
2026-06-011
Patch1
2026-06-161
Disclosure1
2026-06-191
General1
2026-06-231
Disclosure1
2026-06-241
General1
2026-07-022
Disclosure1General1
2026-07-101
Disclosure1
2026-07-311
Disclosure1
2026-08-261
Patch1
2026-08-281
PoC1
Full discourse20 posts
  • tetsuo@tetsuoai
    PoC

    Two years ago, I pushed early boilerplate for CVE-2024-6387 to Git. Hundreds of CN accounts forked it within minutes. I pulled it immediately, given what I was building. Since this exploit has been widely discussed and a patch exists, it's safe to make this public. So I'm doing that now for researchers. Timing primitive, heap groom, full ROP chain. CVE-2024-6387

    Post summary

    The author releases an early PoC for CVE-2024-6387, detailing a heap‑grooming and full ROP chain exploitation approach, and notes that a patch is available.

    948157224833.6K
    241.9K followersView on X
  • GIGAZINE(ギガジン)@gigazine
    Disclosure

    OpenSSHに重大な脅威となる脆弱性「regreSSHion」(CVE-2024-6387)が発覚、ほぼすべてのLinuxシステムに影響(2024) https://t.co/yNYoMIqh69

    Post summary

    The tweet announces the discovery of a critical OpenSSH vulnerability, CVE-2024-6387, noted to affect nearly all Linux systems, without providing any proof‑of‑concept, exploit details, or mitigation information.

    256331017.7K
    610.5K followersView on X
  • s13k@s13k_
    General

    @WilliamBenzDev @levelsio Yes, but things like CVE-2024-6387 (regreSSHion) still possible. https://www.qualys.com/regresshion-cve-2024-6387

    Post summary

    The tweet briefly references CVE-2024-6387 (regreSSHion) and links to a Qualys page, but provides no additional details or actionable information.

    1001572.0K
    5.4K followersView on X
  • AlmaLinux@AlmaLinux
    Patch

    regreSSHion (CVE-2024-6387) shows ALESCo in action: we developed the fix, then shared it upstream with CentOS Stream so the whole ecosystem benefits, not just us. @bennyvasquez and @Det_Conan_Kudo explain. https://t.co/vhK6kxPRXb

    Post summary

    The post announces the development and upstream sharing of a patch for CVE-2024-6387 with CentOS Stream.

    1301801.0K
    12.5K followersView on X
  • BINARLY🔬@binarly_io
    PoC

    Next up is a rule for #regreSSHion (CVE-2024-6387), showcased on an ARM binary, but we've got test cases covering all of VulHunt's supported architectures (x86, x86-64, AArch64, ARM/Thumb). Test case(s): https://github.com/vulhunt-re/tests/tree/main/posix/CVE-2024-6387 Rule: https://github.com/vulhunt-re/rules/blob/main/posix/CVE-2024-6387.vh https://t.co/k9uA3KFaWd

    Post summary

    A rule and accompanying test cases for CVE‑2024‑6387 have been released, covering multiple architectures and providing proof‑of‑concept examples.

    230121662
    4.3K followersView on X
  • Lyra M. 🇺🇦@jingyi_cro
    Patch

    One of the biggest misconceptions in vulnerability management: Seeing OpenSSH 8.7p1 on RHEL doesn't automatically mean CVE-2024-6387 is unpatched. Enterprise distributions heavily rely on backporting. Version numbers can lie. https://access.redhat.com/security/updates/backporting

    Post summary

    The post highlights that OpenSSH 8.7p1 on RHEL may not reflect CVE-2024-6387 status due to backporting, directing readers to RedHat’s update page for patch information.

    2004091
    1.3K followersView on X
  • kernel@kernelshark
    General

    @FranzHackl Joa, bis es mal wieder eine CVE-2024-6387 gibt Warum sollte ich das detailliert prüfen und mich ggf. strafbar machen? Wenn die Daten der Spastis, die sich dort anmelden, veröffentlicht werden, wäre das Karma. Und selbst wenn nicht stirbt der Dienst in 1-2 Jahren ohnehin Egal

    Post summary

    The tweet merely references CVE‑2024‑6387 without providing any technical details, exploit data, or evidence of active use or remediation.

    10040206
    16.2K followersView on X
  • @codejake@codejake
    General

    @MCamblor97 @levelsio Because: possible OpenSSH exploits/zero day unauthenticated RCE. It's happened before: CVE-2024-6387

    Post summary

    A brief mention of CVE-2024-6387 as a potential unauthenticated RCE in OpenSSH, with no further actionable details or evidence of exploitation.

    10022507
    574 followersView on X
  • ngCERT@ngCERTofficial
    Disclosure

    CVE-2024-6387 🚨 (RegreSSHion) A critical flaw in OpenSSH sshd may allow unauthenticated remote code execution with root privileges on vulnerable systems. Further technical guidance will be provided soon #CyberSecurity #Linux https://t.co/Z0Y4Le3AAl

    Post summary

    The tweet announces a critical vulnerability (CVE-2024-6387) in OpenSSH sshd that could lead to unauthenticated root-level remote code execution and notes that more technical guidance will be forthcoming.

    01111205
    1.3K followersView on X
  • CyberSec Intel Alliance@CyberAlliance26
    Active Exploitation

    🚨 ACTIVE EXPLOITS RIGHT NOW: CVE-2024-6387 – OpenSSH regreSSHion Unauthenticated remote code execution against old OpenSSH servers (≤ 4.4p1) CISA just confirmed renewed mass exploitation in the wild (Jan 30/31 KEV update) #CyberSecurity #ThreatIntel #OpenSSH #RCE #PatchNow #LegacyRisk #CVE Thread + what to do 👇

    Post summary

    The post warns that CVE-2024-6387, an unauthenticated RCE in OpenSSH versions ≤4.4p1, is currently being exploited in the wild as confirmed by CISA; it urges action but does not specify a patch.

    11020448
    21 followersView on X
  • ngCERT@ngCERTofficial
    Disclosure

    CRITICAL 🚨 ngCERT identified RegreSSHion (CVE-2024-6387) as a critical unauthenticated Remote Code Execution vulnerability in OpenSSH's sshd on Glibc-based Linux systems which can be exploited through specially crafted requests...... More details below https://cert.gov.ng/advisories/unauthenticated-remote-code-execution-flaw-in-openssh-server-regresshion

    Post summary

    The post announces the discovery of CVE-2024-6387, a critical unauthenticated remote code execution flaw in OpenSSH's sshd on Glibc-based Linux systems, without mentioning PoC, exploitation tools, or mitigation steps.

    01020282
    1.3K followersView on X
  • John McGinnis@JohnMcGinn90325
    Patch

    @CyberRacheal For those that say port 22, you might want to review CVE-2025-32433, CVE-2024-6387, CVE-2025-61984. Need to review version and patch levels and you still might be vulnerable. Remote access should be frontended with a private VPN. Yes I am paranoid.

    Post summary

    The post urges reviewing specific CVEs and patch levels, and recommends using a private VPN for remote access, but it does not provide exploit details or evidence of active attacks.

    1002054
    319 followersView on X
  • GIGAZINE(ギガジン)@gigazine
    General

    https://gigazine.net/news/20240702-regresshion-cve-2024-6387/

    Post summary

    The supplied text consists solely of a URL, providing no explicit details about the CVE or its impact.

    000118.4K
    610.5K followersView on X
  • PatchDayAlert@patchdayalert
    General

    CVE-2024-6387 landed as low priority because exploiting it on 64-bit is slow. But a root RCE in sshd doesn't care how long it takes. We looked at what the CVSS score actually missed. https://patchdayalert.com/blog/regresshion-hard-to-exploit-is-not-a-patch-window/?utm_source=x&utm_medium=social&utm_campaign=blog-tease&utm_content=regresshion-hard-to-exploit-is-not-a-patch-window

    Post summary

    The post remarks that CVE‑2024‑6387 was downgraded to low priority due to slow exploitation on 64‑bit systems, yet it remains a root RCE in sshd, indicating the CVSS score underestimated its impact.

    0100160
    75 followersView on X
  • The Tech Versatilist@wyhycu
    Patch

    Since replies are limited in this thread, I will put this here. This user is likely referring to CVE-2024-6387, which affected Linux and FreeBSD. OpenBSD had corrected this problem since 2001.

    Post summary

    The post identifies CVE‑2024‑6387 affecting Linux and FreeBSD, noting that OpenBSD addressed the issue in 2001, but it provides no exploit details or current patch status.

    10010773
    97 followersView on X
  • Slashr@SlashrDev
    Disclosure

    127 validators are vulnerable to regreSSHion (CVE-2024-6387) — remote code execution in OpenSSH. EPSS: 0.47. That's a 47% chance of active exploitation. 41 of those carry three critical CVEs simultaneously, including two at CVSS 9.8. Concentrated in 4 subnets. Likely 2-3 operators.

    Post summary

    The post discloses that CVE‑2024‑6387 gives remote code execution in OpenSSH, cites EPSS and CVSS metrics, but offers no exploit proof or evidence of active attacks.

    100001
    17 followersView on X
  • Michael Arnaldi@MichaelArnaldi
    Patch

    @wyhycu OP is referring to https://ftp.openbsd.org/pub/OpenBSD/patches/7.8/common/025_sack.patch.sig, I am indeed referring to CVE-2024-6387

    Post summary

    The tweet references the OpenBSD patch signature linked to CVE-2024-6387, indicating that a patch exists for this vulnerability.

    10000508
    7.0K followersView on X
  • Cody 🌴@fresh3nough
    Disclosure

    CVE-2024-6387: RCE in OpenSSH's server, on glibc-based Linux systems source: https://blog.qualys.com/vulnerabili...ode-execution-vulnerability-in-openssh-server PoC: https://xss.is/threads/117932/#post-828747 race condition (because the "#ifdef DO_LOG_SAFE_IN_SIGHAND" was accidentally removed from sigdie()). In our experiments, it takes ~10,000 tries on average to win this race condition, so ~3-4 hours with 100 connections (MaxStartups) accepted per 120 seconds (LoginGraceTime). Ultimately, it takes ~6-8 hours on average to obtain a remote root shell.

    Post summary

    The post announces CVE-2024-6387, an RCE in OpenSSH on glibc-based Linux, provides technical details of the race-condition exploit, and links to a PoC, but does not mention active exploitation, patches, or false positives.

    00010166
    87 followersView on X
  • Bhavesh Verma@xbhaveshverma

    CVEs Explainer #8 CVE-2024-6387 (regreSSHion) A signal handler race condition in OpenSSH's server daemon (sshd) on glibc-based Linux systems. It allowed unauthenticated remote attackers to execute arbitrary code as root, leading to complete system takeover. A regression of an older flaw, regreSSHion highlighted that even the most battle-tested software can harbor critical RCE bugs.‌

    0000061
    103 followersView on X
  • OnetSolutions@OnetSolutions
    Disclosure

    On documente chaque CVE majeure qui touche nos stacks, en français : regreSSHion → https://help.onetsolutions.net/blog/fr/regresshion-cve-2024-6387 xz backdoor → https://help.onetsolutions.net/blog/fr/xz-backdoor-cve-2024-3094

    Post summary

    The message documents two major CVEs (CVE‑2024‑6387 and CVE‑2024‑3094) and provides links to French blog posts that presumably detail each vulnerability.

    0000052
    3.1K followersView on X
CPE platform detail117 entries

117 of 117 entries

PartVendorProductVersionTarget SWTarget HW
OSalmalinuxalmalinux9.0--
OSamazonamazon_linux2023.0--
OSapplemacos---
OSaristaeos---
OScanonicalubuntu_linux22.04--
OScanonicalubuntu_linux22.10--
OScanonicalubuntu_linux23.04--
OScanonicalubuntu_linux23.10--
OScanonicalubuntu_linux24.04--
OSdebiandebian_linux12.0--
OSfreebsdfreebsd13.2--
OSfreebsdfreebsd13.2--
OSfreebsdfreebsd13.2--
OSfreebsdfreebsd13.2--
OSfreebsdfreebsd13.2--
OSfreebsdfreebsd13.2--
OSfreebsdfreebsd13.2--
OSfreebsdfreebsd13.2--
OSfreebsdfreebsd13.2--
OSfreebsdfreebsd13.2--
OSfreebsdfreebsd13.2--
OSfreebsdfreebsd13.2--
OSfreebsdfreebsd13.3--
OSfreebsdfreebsd13.3--
OSfreebsdfreebsd13.3--
OSfreebsdfreebsd13.3--
OSfreebsdfreebsd14.0--
OSfreebsdfreebsd14.0--
OSfreebsdfreebsd14.0--
OSfreebsdfreebsd14.0--
OSfreebsdfreebsd14.0--
OSfreebsdfreebsd14.0--
OSfreebsdfreebsd14.0--
OSfreebsdfreebsd14.0--
OSfreebsdfreebsd14.0--
OSfreebsdfreebsd14.0--
OSfreebsdfreebsd14.0--
OSfreebsdfreebsd14.1--
OSfreebsdfreebsd14.1--
HWnetapp500f---
OSnetapp500f_firmware---
HWnetapp8300---
OSnetapp8300_firmware---
HWnetapp8700---
OSnetapp8700_firmware---
HWnetappa150---
OSnetappa150_firmware---
HWnetappa1k---
OSnetappa1k_firmware---
HWnetappa220---
OSnetappa220_firmware---
HWnetappa250---
OSnetappa250_firmware---
HWnetappa400---
OSnetappa400_firmware---
HWnetappa70---
HWnetappa700s---
OSnetappa700s_firmware---
OSnetappa70_firmware---
HWnetappa800---
OSnetappa800_firmware---
HWnetappa90---
HWnetappa900---
OSnetappa900_firmware---
OSnetappa90_firmware---
HWnetappa9500---
OSnetappa9500_firmware---
Appnetappactive_iq_unified_manager-vmware_vsphere-
OSnetappbootstrap_os---
HWnetappc190---
OSnetappc190_firmware---
HWnetappc250---
OSnetappc250_firmware---
HWnetappc400---
OSnetappc400_firmware---
HWnetappc800---
OSnetappc800_firmware---
Appnetappe-series_santricity_os_controller---
HWnetappfas2720---
OSnetappfas2720_firmware---
HWnetappfas2750---
OSnetappfas2750_firmware---
HWnetappfas2820---
OSnetappfas2820_firmware---
HWnetapphci_compute_node---
Appnetappontap9--
Appnetappontap_select_deploy_administration_utility---
Appnetappontap_tools10vmware_vsphere-
Appnetappontap_tools9vmware_vsphere-
OSnetbsdnetbsd---
Appopenbsdopenssh---
Appopenbsdopenssh4.4--
Appopenbsdopenssh8.5--
Appopenbsdopenssh8.6--
OSredhatenterprise_linux9.0--
OSredhatenterprise_linux_eus9.4--
OSredhatenterprise_linux_for_arm_649.0_aarch64--
OSredhatenterprise_linux_for_arm_64_eus9.4_aarch64--
OSredhatenterprise_linux_for_ibm_z_systems9.0_s390x--
OSredhatenterprise_linux_for_ibm_z_systems_eus9.4_s390x--
OSredhatenterprise_linux_for_power_little_endian9.0_ppc64le--
OSredhatenterprise_linux_for_power_little_endian_eus9.4_ppc64le--
OSredhatenterprise_linux_server_aus9.4--
Appredhatopenshift_container_platform4.0--
HWsonicwallsma_6200---
OSsonicwallsma_6200_firmware---
HWsonicwallsma_6210---
OSsonicwallsma_6210_firmware---
HWsonicwallsma_7200---
OSsonicwallsma_7200_firmware---
HWsonicwallsma_7210---
OSsonicwallsma_7210_firmware---
HWsonicwallsma_8200v---
OSsonicwallsma_8200v_firmware---
HWsonicwallsra_ex_7000---
OSsonicwallsra_ex_7000_firmware---
OSsuselinux_enterprise_micro6.0--

Explore more