A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.
CVE-2024-6387
Score elevated to 9.0 because EPSS predicts 100% probability of exploitation within the next 30 days (99th percentile of EPSS-scored CVEs). NVD baseline CVSS 8.1 retained for reference. Confidence: see factors.
- 4,205 internet-facing services (distinct ip:port) on record running an affected version — derived from Shodan data (© Shodan); a patched service can stay counted while its port stays open
- High exploitation likelihood — EPSS 100%
- Public exploit code is available (ssvc poc, epss top5pct, epss high, public exploit)
A fix is available — apply it.
4,205 internet-facing services (distinct ip:port) on record running a version that maps to CVE-2024-6387, in our KEV-Exposure radar’s Shodan-derived sample.
How it counts: every 12 hours, when Shodan query credits allow, the radar runs one Shodan query per tracked product, reads up to 100 ip:port services per query, and keeps a service when its banner version matches a CISA-KEV or high-EPSS CVE; a service is dropped when neither a search nor a Shodan InternetDB port re-check has refreshed it for 21 days. A re-check that finds the port still listed by Shodan InternetDB refreshes the service without re-reading the banner, so a patched service can stay counted while its port stays open. A count is a banner-version inference over a sample, not an exploit test and not an internet-wide census, and the unit is a service, not a machine: a machine answering on two ports counts twice.
- CVSS v3
- 8.1
- EG Score
- 9.0CRITICALhigh confidence
- EG Risk
- 80EG Risk 80/100CISA SSVC
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity90% × 45%Exploitation100% × 40%Automatability0% × 15%CISA SSVC: Track at low, Track* at medium and Attend at high mission impact.Action: A fix is available. Apply it within your standard update timelines at low or medium mission impact and sooner than that at high. - EPSS PROB
- 100%
- EPSS %ILE
- 99th
- KEV
- Not listed
CISA SSVCTrack at low, Track* at medium and Attend at high mission impact.
A fix is available. Apply it within your standard update timelines at low or medium mission impact and sooner than that at high.
Exploitation public PoC (CISA Vulnrichment) · Automatable no (CISA Vulnrichment) · Technical impact total (CISA Vulnrichment). Mission impact is CISA's Mission & Well-being decision point, and only you can judge it: high means the affected system is essential to your organisation's mission, or its compromise could cause irreversible harm to people. CISA's decision table
Published
July 1, 2024
Last Modified
September 1, 2026
Advisory Details (10)
Auto-updated May 12, 2026blog | The public blog of Santander Cyber Security Research
https://santandersecurityresearch.github.io/blog/sshing_the_masses.html2294604 – (CVE-2024-6387, regreSSHion) CVE-2024-6387 openssh: regreSSHion - race condition in SSH allows RCE/DoS
Affected: Red Hat Enterprise Linux 9
https://bugzilla.redhat.com/show_bug.cgi?id=2294604Affected: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions.
https://access.redhat.com/errata/RHSA-2024:4389Affected: Red Hat Enterprise Linux 9.2 Extended Update Support.
https://access.redhat.com/errata/RHSA-2024:4340Affected: Red Hat Enterprise Linux 9.
https://access.redhat.com/errata/RHSA-2024:4312Vendor Advisories for CVE-2024-6387(9)
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
- CVE-2024-6387Microsoft Security Response Center (MSRC)Critical
RedHat Openssh: CVE-2024-6387 Remote Code Execution Due To A Race Condition In Signal Handling
- RHSA-2024:4474Red Hat Product SecurityHigh
Red Hat Security Advisory: OpenShift Container Platform 4.15.22 security update
- RHSA-2024:4484Red Hat Product SecurityHigh
Red Hat Security Advisory: OpenShift Container Platform 4.13.45 bug fix and security update
- RHSA-2024:4479Red Hat Product SecurityHigh
Red Hat Security Advisory: OpenShift Container Platform 4.14.33 bug fix and security update
- RHSA-2024:4469Red Hat Product SecurityHigh
Red Hat Security Advisory: OpenShift Container Platform 4.16.3 security update
- RHSA-2024:4389Red Hat Product SecurityHigh
Red Hat Security Advisory: openssh security update
- RHSA-2024:4340Red Hat Product SecurityHigh
Red Hat Security Advisory: openssh security update
- RHSA-2024:4312Red Hat Product SecurityHigh
Red Hat Security Advisory: openssh security update
- +1 more
Patch Availability(8)
| Vendor / Ecosystem | Fix (by version range) / Patch | Released | Source |
|---|---|---|---|
| ubuntu | ssh-askpass-gnome (1:9.6p1-3ubuntu13.3) @ noble | 2026-05-22 | ubuntu |
| redhat | rhcos-415.92.202407091355-0 | 2024-07-18 | redhat |
| redhat | rhcos-413.92.202407091321-0 | 2024-07-17 | redhat |
| redhat | rhcos-414.92.202407091253-0 | 2024-07-17 | redhat |
| redhat | rhcos-416.94.202407081958-0 | 2024-07-16 | redhat |
| redhat | openssh-0:8.7p1-12.el9_0.1 | 2024-07-08 | redhat |
| redhat | openssh-0:8.7p1-30.el9_2.4 | 2024-07-05 | redhat |
| redhat | openssh-0:8.7p1-38.el9_4.1 | 2024-07-03 | redhat |
Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.
Affected Packages
(11 across 11 ecosystems)
Alpine:v3.17(1)
| Package | Vulnerable range | Fix by version range | Dependents |
|---|---|---|---|
| openssh | — |
| — |
Alpine:v3.18(1)
| Package | Vulnerable range | Fix by version range | Dependents |
|---|---|---|---|
| openssh | — |
| — |
Alpine:v3.19(1)
| Package | Vulnerable range | Fix by version range | Dependents |
|---|---|---|---|
| openssh | — |
| — |
Alpine:v3.20(1)
| Package | Vulnerable range | Fix by version range | Dependents |
|---|---|---|---|
| openssh | — |
| — |
Alpine:v3.21(1)
| Package | Vulnerable range | Fix by version range | Dependents |
|---|---|---|---|
| openssh | — |
| — |
Alpine:v3.22(1)
| Package | Vulnerable range | Fix by version range | Dependents |
|---|---|---|---|
| openssh | — |
| — |
Alpine:v3.23(1)
| Package | Vulnerable range | Fix by version range | Dependents |
|---|---|---|---|
| openssh | — |
| — |
Alpine:v3.24(1)
| Package | Vulnerable range | Fix by version range | Dependents |
|---|---|---|---|
| openssh | — |
| — |
Debian:12(1)
| Package | Vulnerable range | Fix by version range | Dependents |
|---|---|---|---|
| openssh | 1:9.2p1-2, 1:9.2p1-2+deb12u1, 1:9.2p1-2+deb12u2 |
| — |
Debian:13(1)
| Package | Vulnerable range | Fix by version range | Dependents |
|---|---|---|---|
| openssh | — |
| — |
Debian:14(1)
| Package | Vulnerable range | Fix by version range | Dependents |
|---|---|---|---|
| openssh | — |
| — |
Weakness Classification(2)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Additional Vendor Advisories
(1)
Vendors that published advisories for this CVE beyond the curated set above. Broader coverage but minimal per-row detail — click through for the original advisory.
Data Freshness Timeline
(refreshed 1× in last 7d / 5× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-10-10 00:55 UTCOSV refresh
- 2026-10-02 16:28 UTCEG score recompute
- 2026-09-20 20:14 UTCEPSS rescore
- 2026-09-20 20:14 UTCEPSS rescore
- 2026-09-20 09:03 UTCOSV refresh
- 2026-09-08 21:59 UTCEPSS rescore
- 2026-09-06 13:46 UTCEPSS rescore
- 2026-09-01 12:33 UTCVendor advisory
- 2026-09-01 12:33 UTCGHSA enrichment
- 2026-09-01 11:17 UTCVendor advisory
- 2026-09-01 11:17 UTCGHSA enrichment
- 2026-08-31 17:28 UTCEG score recompute
- 2026-08-31 17:28 UTCVendor advisory
- 2026-08-31 17:27 UTCGHSA enrichment
- 2026-08-31 17:02 UTCEG score recompute
- 2026-08-31 17:02 UTCVendor advisory
- 2026-08-31 17:02 UTCGHSA enrichment
- 2026-08-28 21:39 UTCEPSS rescore
- 2026-08-24 14:15 UTCEPSS rescore
- 2026-08-24 07:57 UTCOSV refresh
- 2026-08-19 17:02 UTCEPSS rescore
- 2026-08-18 13:47 UTCEPSS rescore
- 2026-08-16 02:13 UTCEPSS rescore
- 2026-08-08 04:19 UTCOSV refresh
- 2026-08-04 15:08 UTCEPSS rescore
Show 67 moreShow fewer
- 2026-08-03 10:35 UTCEPSS rescore
- 2026-08-02 02:25 UTCEPSS rescore
- 2026-08-02 02:25 UTCEPSS rescore
- 2026-07-25 14:17 UTCEPSS rescore
- 2026-07-25 14:17 UTCEPSS rescore
- 2026-07-23 02:46 UTCEG score recompute
- 2026-07-22 21:20 UTCEG score recompute▲ 0.90
- 2026-07-22 21:20 UTCVendor advisory
- 2026-07-22 21:19 UTCGHSA enrichment
- 2026-07-21 15:23 UTCEPSS rescore
- 2026-07-19 14:30 UTCEPSS rescore
- 2026-07-19 14:30 UTCEPSS rescore
- 2026-07-15 16:57 UTCEPSS rescore
- 2026-07-11 03:52 UTCOSV refresh
- 2026-07-06 16:26 UTCEPSS rescore
- 2026-07-06 16:26 UTCEPSS rescore
- 2026-06-22 11:02 UTCOSV refresh
- 2026-06-16 17:52 UTCEPSS rescore
- 2026-06-15 17:48 UTCEPSS rescore
- 2026-06-12 23:11 UTCEPSS rescore
- 2026-06-12 23:11 UTCEPSS rescore
- 2026-06-11 13:59 UTCEPSS rescore
- 2026-06-11 13:59 UTCEPSS rescore
- 2026-06-10 22:18 UTCEPSS rescore
- 2026-06-10 22:18 UTCEPSS rescore
- 2026-06-10 13:21 UTCEPSS rescore
- 2026-06-08 14:16 UTCEPSS rescore
- 2026-06-08 14:16 UTCEPSS rescore
- 2026-06-07 15:24 UTCEPSS rescore
- 2026-06-07 15:24 UTCEPSS rescore
- 2026-06-06 13:46 UTCEPSS rescore
- 2026-06-06 13:46 UTCEPSS rescore
- 2026-06-05 22:46 UTCEPSS rescore
- 2026-06-05 22:46 UTCEPSS rescore
- 2026-06-05 06:09 UTCEPSS rescore
- 2026-06-05 06:09 UTCEPSS rescore
- 2026-06-04 15:39 UTCOSV refresh
- 2026-06-02 20:12 UTCEPSS rescore
- 2026-06-02 20:12 UTCEPSS rescore
- 2026-06-01 13:51 UTCEPSS rescore
- 2026-06-01 13:51 UTCEPSS rescore
- 2026-06-01 13:51 UTCEPSS rescore
- 2026-05-31 22:30 UTCEPSS rescore
- 2026-05-31 22:30 UTCEPSS rescore
- 2026-05-31 00:16 UTCEPSS rescore
- 2026-05-31 00:16 UTCEPSS rescore
- 2026-05-29 13:43 UTCEPSS rescore
- 2026-05-28 13:44 UTCEPSS rescore
- 2026-05-28 13:44 UTCEPSS rescore
- 2026-05-28 13:44 UTCEPSS rescore
- 2026-05-27 13:40 UTCEPSS rescore
- 2026-05-27 13:40 UTCEPSS rescore
- 2026-05-22 21:16 UTCEPSS rescore
- 2026-05-22 21:16 UTCEPSS rescore
- 2026-05-22 21:16 UTCEPSS rescore
- 2026-05-22 21:16 UTCEPSS rescore
- 2026-05-22 00:36 UTCEG score recompute
- 2026-05-22 00:36 UTCVendor advisory
- 2026-05-22 00:36 UTCGHSA enrichment
- 2026-05-21 22:42 UTCEPSS rescore
- 2026-05-20 22:37 UTCEPSS rescore
- 2026-05-20 22:37 UTCEPSS rescore
- 2026-05-20 22:37 UTCEPSS rescore
- 2026-05-20 22:37 UTCEPSS rescore
- 2026-05-20 22:37 UTCEPSS rescore
- 2026-05-18 21:30 UTCEPSS rescore
- 2026-05-18 21:30 UTCEPSS rescore
Publicly available exploits
(12 references, 10 shown)Public exploit code is referenced for this CVE (1 Exploit-DB entry, 11 GitHub PoCs). Defenders should treat patch urgency accordingly.
- Exploit-DBEDB-52269Published Apr 22, 2025
OpenSSH server (sshd) 9.8p1 - Race Condition
Open source ↗ - GitHub PoCfilipi86/CVE-2024-6387-Vulnerability-CheckerPublished Jul 9, 2024
This Python script checks for the CVE-2024-6387 vulnerability in OpenSSH servers. It supports multiple IP addresses, URLs, CIDR ranges, and ports. The script can also read addresses from a file.
Open source ↗ - GitHub PoCKarmakstylez/CVE-2024-6387Published Jul 8, 2024
Remote Unauthenticated Code Execution Vulnerability in OpenSSH server (CVE-2024-6387)
Open source ↗ - GitHub PoCzgzhang/cve-2024-6387-pocPublished Jul 3, 2024
Reproduction PoC for the OpenSSH signal-handler race condition (32-bit demo).
Open source ↗ - GitHub PoCd0rb/CVE-2024-6387Published Jul 2, 2024
This Python script exploits a remote code execution vulnerability (CVE-2024-6387) in OpenSSH.
Open source ↗ - GitHub PoCl0n3m4n/CVE-2024-6387Published Jul 2, 2024
PoC - Remote Unauthenticated Code Execution Vulnerability in OpenSSH server (Scanner and Exploit)
Open source ↗ - GitHub PoCxonoxitron/regreSSHionPublished Jul 2, 2024
CVE-2024-6387 (regreSSHion) Exploit (PoC), a vulnerability in OpenSSH's server (sshd) on glibc-based Linux systems.
Open source ↗ - GitHub PoCacrono/cve-2024-6387-pocPublished Jul 1, 2024
32-bit PoC for CVE-2024-6387 — mirror of the original 7etsuo/cve-2024-6387-poc
Open source ↗ - GitHub PoCbigb0x/CVE-2024-6387Published Jul 1, 2024
Bulk Scanning Tool for OpenSSH CVE-2024-6387, CVE-2006-5051 , CVE-2008-4109 and others.
Open source ↗ - GitHub PoCgetdrive/CVE-2024-6387-PoCPublished Jul 1, 2024
PoC RCE in OpenSSH
Open source ↗
Past incidents using this CVE
(1)This CVE was central to one or more publicly-documented breaches. Each card links to authoritative reporting at the time of the incident.
- regreSSHion (OpenSSH)Jul 2024
Signal-handler race condition in OpenSSH sshd allowed unauthenticated RCE as root on glibc-based Linux systems. Qualys disclosed; affected millions of internet-facing sshd instances.
Source: Qualys
Related CVEs(same product + same vendor + same CWE)
Same product
10 shownAlpine:v3.18:openssh
- CVE-2023-48795NVD 5.9EG 9.0EPSS p100CRITICAL
- CVE-2018-15473NVD 5.3EG 9.0EPSS p100CRITICAL
- CVE-2016-10012EG 7.8HIGH
- CVE-2019-6111NVD 5.9EG 7.5EPSS p99HIGH
- CVE-2016-10009NVD 7.3EG 7.5EPSS p98HIGH
- CVE-2021-28041EG 7.1HIGH
- CVE-2021-41617EG 7.0HIGH
- CVE-2016-10010EG 7.0EPSS p91HIGH
- CVE-2019-6109EG 6.8EPSS p90MEDIUM
- CVE-2016-10011EG 6.2MEDIUM
Same vendor
5 shownredhat:RHSA-2024:4479 · redhat:RHSA-2024:4469 · redhat:RHSA-2024:4484
Frequently asked(5)
What is CVE-2024-6387?
When was CVE-2024-6387 disclosed?
Is CVE-2024-6387 actively exploited?
What is the CVSS score of CVE-2024-6387?
How do I remediate CVE-2024-6387?
Dependency Blast Radius
See which npm, PyPI, Go, and Maven packages are affected by CVE-2024-6387
Is Your Infrastructure Affected by CVE-2024-6387?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.