-
Notifications
You must be signed in to change notification settings - Fork 60
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
CVE-2024-6387: OpenSSH 9.8: regreSSHion: RCE in OpenSSH's server, on glibc-based Linux systems #1754
Comments
Technically it's pending a package update in Fedora. |
Update with the backported fix for F40 https://bodhi.fedoraproject.org/updates/FEDORA-2024-dc89a2e1bf |
I did https://github.com/coreos/fedora-coreos-config/actions/runs/9757857281 to fast-track it and it gets me:
|
Did a manual fasttrack: coreos/fedora-coreos-config#3047 |
Alternative mitigation in https://social.treehouse.systems/@marcan/112715795823895634:
|
This was fixed in testing 40.20240701.2.0 and next 40.20240701.1.0. Currently, we are not planning an ad-hoc release for stable; it'll ship in stable next week. |
The fix for this went into |
See:
They only have working exploits for i686 right now.
The configuration workarounds are not ideal unfortunately: https://lwn.net/ml/all/[email protected]/
The text was updated successfully, but these errors were encountered: