A new CVE was released on Monday, July 1, 2024, for OpenSSH, a tool widely used for remote Linux server administration. This vulnerability, identified as CVE-2024-6387 and codenamed regreSSHion, allows for unauthenticated remote code execution with administrative privileges on vulnerable servers.
What is OpenSSH?
OpenSSH (OpenBSD Secure Shell) is a suite of tools that enables secure communication with a server over insecure networks. OpenSSH is an implementation of the SSH (Secure Shell) protocol and is extensively used to manage Linux servers: a search on Shodan.io, for instance, reveals over 23 million OpenSSH ports publicly exposed on the internet.
What is the CVE-2024-6387 vulnerability?
CVE-2024-6387 is a high-severity vulnerability (CVSSv3.1 score of 8.1/10), highlighted in an alert from ANSSI (the French National Cybersecurity Agency) in its bulletin CERTFR-2024-ALE-009.
This CVE is caused by a race condition, a situation where an attacker can manipulate the execution of multiple processes to force a program to behave in an unintended way.
How does CVE-2024-6387 work?
CVE-2024-6387 is a race condition. This vulnerability exploits the fact that an OpenSSH client establishing communication with an OpenSSH server is normally granted a specific timeframe to authenticate. This timeframe is configured using a parameter named LoginGraceTime. When this time limit is exceeded, a SIGALRM (timeout signal) is triggered asynchronously by OpenSSH. As a reminder, a signal is an asynchronous inter-process communication system used to indicate that an event has occurred.
The SIGALRM signal generated by LoginGraceTime is subsequently handled by processes that are not "async-signal-safe," meaning these processes do not verify whether the memory state has remained consistent between the time the signal was issued and the time it was received. In this case, the syslog process intercepts SIGALRM and uses memory allocation and deallocation functions (malloc and free).
An attacker can then send data to the targeted server using a specially crafted SSH public key. While reading this public key, the server allocates memory (using the malloc function). If a SIGALRM signal occurs during this memory allocation, it is possible to trigger calls to malloc and free within syslog in a way that causes an inconsistent memory state, leading to code execution.
Note that exploiting this vulnerability requires numerous attempts and therefore takes a significant amount of time (approximately 8 hours on a 32-bit system).
How to exploit CVE-2024-6387 on OpenSSH?
Exploiting CVE-2024-6387 requires a statistical approach where the attacker sends numerous SSH authentication sequences, timing them so that the SIGALRM signal (linked to the LoginGraceTime limit) triggers while the server is loading the attacker's public key into memory.
As of the writing of this article, no simple public exploit is recognized by the community.
CVE-2024-6387: which systems are affected?
CVE-2024-6387 affects a wide range of OpenSSH versions, depending on their configuration:
- Certain configurations of OpenSSH versions strictly earlier than 4.4p1 are vulnerable;
- OpenSSH from version 8.5p1 up to, but not including, version 9.8p1.
In practice, since OpenSSH is rarely used directly in one of these versions, but rather installed via Linux distribution package managers, we can establish the following list:
- Debian (source): Debian 11 not affected; Debian 12 vulnerable under 1:9.2p1-deb12u3; Debian SID vulnerable under 1:9.7p1-7.
- Alpine Linux : Edge vulnerable in 9.8_p1-r0; 3.17 in 9.8_p1-r6; 3.18 in 9.3_p2-r2; 3.19 in 9.6_p1-r1.
- Amazon Linux (source) : Amazon Linux 2023 vulnerable in 8.7p1-8.amzn2023.0.11.
- ArchLinux (source) : vulnerable in 9.8p1-1.
- Oracle Linux (source) : versions 6, 7, and 8 not affected; Oracle Linux 9 vulnerable in 8.7p1-38.0.2.el9.
- Palo Alto (source) : no products affected.
- Red Hat (source) : RHEL 6, 7, and 8 are not affected; RHEL 9 is vulnerable below 8.7p1-38.el9_4.1.
- SUSE (source) : SUSE 15 SP6 is vulnerable below 9.6p1-150600.6.3.1.
- Ubuntu (source) : 22.04 is vulnerable below 1:8.9p1-3ubuntu0.10; 23.10 below 1:9.3p1-1ubuntu3.6; 24.04 below 1:9.6p1-3ubuntu13.3.
- VMware PhotonOS (source) : PhotonOS 4 is vulnerable below 8.9p1-8.ph4.x86_64; PhotonOS 5 below 9.3p2-9.ph5.x86_64.
Other distributions will almost certainly announce their exposure to this vulnerability in the coming hours, and this page will be updated accordingly.
I am using a system affected by CVE-2024-6387, what should I do?
Cyberwatch recommends applying the security patches provided by your distribution as soon as possible.
Additionally, Cyberwatch recommends checking SSHD logs to monitor all incoming connections.
If an update is not possible, setting LoginGraceTime to 0 will neutralize the vulnerability, but may lead to a loss of server availability. Deploying security patches is therefore strongly recommended.
How can I detect CVE-2024-6387?
Check if you are using one of the OpenSSH versions mentioned earlier in this article.
Users of the Cyberwatch CTEM platform can already detect this vulnerability as of July 1, 2024. Please feel free to contact our team for any information requests.
Change log
07/01/2024 at 11:33 PM GMT+2: initial version
07/02/2024 at 11:30 AM GMT+2: added vulnerable systems
07/03/2024 at 01:25 AM GMT+2: added vulnerable systems following new vendor publications
07/03/2024 at 09:15 PM GMT+2: added Red Hat security advisory with patch.
