[ << ALL_FEED ]

What happened to OpenSSH security in 2024

More in General

What happened to OpenSSH security in 2024 🚪

Let’s look at the timeline:

• Spring. Backdoor in xz-utils (CVE-2024-3094). As a result of its introduction, systems with systemd were compromised, where OpenSSH has a dependency on liblzma, which is not originally present in OpenSSH and is not directly used by OpenSSH itself (meaning this is more about a supply chain attack on those distributions rather than specifically on OpenSSH).

• July. A critically dangerous race condition vulnerability for systems based on glibc, named regreSSHion (CVE-2024-6387), which is a resurrection of CVE-2006-5051.

• Same July. A similar issue was published, assigned identifier CVE-2024-6409.

• August. Another one, specific to FreeBSD, CVE-2024-7589.

❔ What was all this about

Researchers claim that successful exploitation of the race conditions allows achieving RCE on vulnerable systems. Moreover, regreSSHion — the main bug (affecting the privileged sshd process) — compromises the security of many SSH servers running glibc. Exploiting the vulnerability does not require any special server configuration (the issue is also relevant for the default configuration). However, there is still no public PoC to date.

We decided to investigate how dangerous these race conditions really are and what mechanisms in sshd are designed to prevent exploitation of this vulnerability or at least mitigate the damage in case of a successful attack. Along the way, we also reviewed the other OpenSSH vulnerabilities from the past year.

🔣 And now all of this, with technical foundations and a 30-second digression, is available in our blog on Habr. Enjoy!

#CVE #escvr
@ptescalator

More from author_vr

More from author_vr

More in General