https://nvd.nist.gov/vuln/detail/CVE-2024-6387


https://ubuntu.com/security/CVE-2024-6387

PACKAGERELEASE
STATUS
openssh
Launchpad, Ubuntu, Debian
bionic18.04Not vulnerable (introduced in v8.5p1)
focal20.04Not vulnerable (introduced in v8.5p1)
jammy22.04Released (1:8.9p1-3ubuntu0.10)
mantic23.10Released (1:9.3p1-1ubuntu3.6)
noble24.04Released (1:9.6p1-3ubuntu13.3)
trusty14.04Not vulnerable (introduced in v8.5p1)
xenial16.04Not vulnerable (introduced in v8.5p1)
upstream
Pending (9.8p1)

apt update
apt install openssh-{client,server}


https://security-tracker.debian.org/tracker/CVE-2024-6387

Source PackageReleaseVersionStatus
openssh (PTS)bullseye (security), bullseye1:8.4p1-5+deb11u3fixed

bookworm1:9.2p1-2+deb12u2vulnerable

bookworm (security)1:9.2p1-2+deb12u3fixed

sid, trixie1:9.7p1-7fixed


https://rockylinux.org/news/2024-07-01-openssh-sigalrm-regression

dnf install rocky-release-security
dnf config-manager --disable security-common
dnf --enablerepo=security-common update openssh\*