CVE-2024-7589General(freebsd / freebsd)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A signal handler in sshd(8) may call a logging function that is not async-signal-safe. The signal handler is invoked when a client does not authenticate within the LoginGraceTime seconds (120 by default). This signal handler executes in the context of the sshd(8)'s privileged code, which is not sandboxed and runs with full root privileges. This issue is another instance of the problem in CVE-2024-6387 addressed by FreeBSD-SA-24:04.openssh. The faulty code in this case is from the integration of blacklistd in OpenSSH in FreeBSD. As a result of calling functions that are not async-signal-safe in the privileged sshd(8) context, a race condition exists that a determined attacker may be able to exploit to allow an unauthenticated remote code execution as root.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-362CWE-364

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • freebsd

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
freebsd

3 versions affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-10: 1Technical Details · 2026-07-10: 107-10
Signal classification1 categories
General
1100.0%
Referenced assets6 URLs
Full discourse1 post
  • Vivian Voss@vivianvossnet
    General

    ▌ The Bug in the Gap Last Friday ended on a question: when one of these surfaces gives, who patches it, and how fast can you trust the patch? Pick a morning everyone remembers. 1 July 2024. Qualys publishes regreSSHion (CVE-2024-6387): a signal-handler race in OpenSSH's server, unauth root on glibc Linux. This is the OpenSSH on every server you own. The bug is not the interesting part; bugs arrive like weather. The answer is. On FreeBSD it was one advisory, six branches corrected between 08:22:13 and 08:27:53 UTC: five minutes and forty seconds. On Linux it arrived as a week of distro advisories, each on its own calendar. Same patch, very different times before you could call it handled. ■ THE BREACH The November 2025 runc break-outs (CVE-2025-31133, -52565, -52881) show where the bug lived. An attacker swaps a device file for a symlink into procfs; runc bind-mounts it read-write, and a write meant for /dev/null lands in /proc/sysrq-trigger. Put each part in the witness box: procfs behaved as documented, namespaces as promised, runc as asked. Each has an alibi; the prisoner escaped anyway, in the one place no one watched: the seam. ■ THE PATTERN Individually correct, collectively wrong. In 2020 the kernel added faccessat2; glibc 2.33 preferred it; the container seccomp list did not. Three correct choices, and a program asking to read a file is refused. Four parties, each in the right, had fitted a locked door nobody ordered: what happens when everyone minds their component and no one minds the gaps. The repair scatters too: CIQ, who ship their own enterprise Linux, counted 4,594 upstream-fixed bugs never back-ported into RHEL 8.8. Not a backlog a fortnight clears: a standing condition. ■ THE LIMIT Containers earned their place: portability, density, legible deployment. And FreeBSD does not get to look serene: weeks after regreSSHion it shipped CVE-2024-7589, another root hole in its own sshd, from its own blocklistd integration. Lower defect density. Not zero. Anyone selling zero has something else to sell. ■ THE BSD ANGLE A jail (FreeBSD 4.0, 2000) is one kernel object: the boundary sits in the syscall layer, not assembled from four subsystems that read one surface three ways. No four parties, no seam to slip between: a bug cannot hide in a gap that was never opened. And one tree, kernel and libc from the same commit, so a faccessat2 gap cannot open. The scattered week and the five-minute window are not two work ethics. They are two architectures. ■ THE POINT You do not choose your bugs. You choose your defect density, decided the day the system was designed. When regreSSHion lands on the integrated system, the hard morning is over before it began, and nobody writes up the incident, because there is none. Boring is not the absence of engineering. It is engineering, banked early, paying out on your worst morning. The third and last of Boring on Purpose. #freebsd #security #linux #containers #openssh *** Read the primary sources and weigh the tree yourself: → Full essay: https://vivianvoss.net/blog/the-bug-in-the-gap → regreSSHion (CVE-2024-6387), Qualys: https://blog.qualys.com/vulnerabilities-threat-research/2024/07/01/regresshion-remote-unauthenticated-code-execution-vulnerability-in-openssh-server → FreeBSD-SA-24:04, six branches in five minutes: https://lists.freebsd.org/archives/freebsd-security-notifications/2024-July/000038.html → runc break-outs via procfs writes (Nov 2025): https://seclists.org/oss-sec/2025/q4/138 → CIQ, 4,594 un-backported fixes in RHEL 8.8: https://ciq.com/blog/new-research-the-red-hat-linux-kernel-model-is-broken-and-cant-be-fixed/ → FreeBSD's own OpenSSH RCE (CVE-2024-7589): https://thehackernews.com/2024/08/freebsd-releases-urgent-patch-for-high.html

    Post summary

    The post describes the timing delays in patching CVE‑2024‑6387 and related vulnerabilities across platforms, focusing on the differences in patch release cadence rather than providing evidence of exploitation or a PoC.

    00000102
    5 followersView on X
CPE platform detail18 entries

18 of 18 entries

PartVendorProductVersionTarget SWTarget HW
OSfreebsdfreebsd---
OSfreebsdfreebsd13.3--
OSfreebsdfreebsd13.3--
OSfreebsdfreebsd13.3--
OSfreebsdfreebsd13.3--
OSfreebsdfreebsd14.0--
OSfreebsdfreebsd14.0--
OSfreebsdfreebsd14.0--
OSfreebsdfreebsd14.0--
OSfreebsdfreebsd14.0--
OSfreebsdfreebsd14.0--
OSfreebsdfreebsd14.0--
OSfreebsdfreebsd14.0--
OSfreebsdfreebsd14.0--
OSfreebsdfreebsd14.0--
OSfreebsdfreebsd14.0--
OSfreebsdfreebsd14.1--
OSfreebsdfreebsd14.1--

Explore more