CVE-2024-6409High· 7.0▾ TwilightA race condition vulnerability was discovered in how signals are handled by OpenSSH's server (sshd). If a remote attacker does not authenticate within a set time period, then sshd's SIGALRM handler is called asynchronously. However, this…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 38.5 · likelihood 5.6 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 21.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
28%
A race condition vulnerability was discovered in how signals are handled by OpenSSH's server (sshd). If a remote attacker does not authenticate within a set time period, then sshd's SIGALRM handler is called asynchronously. However, this signal handler calls various functions that are not async-signal-safe, for example, syslog(). As a consequence of a successful attack, in the worst case scenario, an attacker may be able to perform a remote code execution (RCE) as an unprivileged user running the sshd server.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2024-6387High· 8.1A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd)
CVE-2026-92067High· 8.8Use-after-free in the Widget: Gtk component
CVE-2026-80991Medium· 5.5kernel: net: ravb: serialize PTP clock teardown (CVE-2026-80991)
CVE-2026-89472Medium· 5.5kernel: power: supply: charger-manager: register regulators before exposing sysfs (CVE-2026-89472)
CVE-2026-89654High· 7.0kernel: ceph: fix UAF in check_new_map() on session freed during unlock (CVE-2026-89654)
CVE-2026-80932Medium· 5.5kernel: vsock/virtio: flush works in dependency order (CVE-2026-80932)