CVE-2024-6387

✓ Confirmed 0-Day
Triaged: March 5, 2026 6 articles Published: 2024-07-01

EPSS Score

Source: FIRST.org · 2026-05-24
63.05%
probability
This CVE has a 63.05% probability of being exploited in the next 30 days.
0% Top 98.4th percentile of all CVEs 100%

CVSS v3.1

Source: VulnerabilityLookup (CIRCL)
8.1
HIGH
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

VulnerabilityLookup (CNA)
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.

Affected Products

8.5p1
Red Hat
Red Hat Enterprise Linux 9
0:8.7p1-38.el9_4.1
Red Hat
Red Hat Enterprise Linux 9
0:8.7p1-38.el9_4.1
Red Hat
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
0:8.7p1-12.el9_0.1
Red Hat
Red Hat Enterprise Linux 9.2 Extended Update Support
0:8.7p1-30.el9_2.4

Exploits & PoC

xaitax/CVE-2024-6387_Check

CVE-2024-6387_Check is a lightweight, efficient tool designed to identify servers running vulnerable versions of OpenSSH

522
zgzhang/cve-2024-6387-poc

a signal handler race condition in OpenSSH's server (sshd)

492
acrono/cve-2024-6387-poc

32-bit PoC for CVE-2024-6387 — mirror of the original 7etsuo/cve-2024-6387-poc

382
Karmakstylez/CVE-2024-6387

Remote Unauthenticated Code Execution Vulnerability in OpenSSH server (CVE-2024-6387)

179
lflare/cve-2024-6387-poc

MIRROR of the original 32-bit PoC for CVE-2024-6387 "regreSSHion" by 7etsuo/cve-2024-6387-poc

126
l0n3m4n/CVE-2024-6387

PoC - Remote Unauthenticated Code Execution Vulnerability in OpenSSH server (Scanner and Exploit)

101
filipi86/CVE-2024-6387-Vulnerability-Checker

This Python script checks for the CVE-2024-6387 vulnerability in OpenSSH servers. It supports multiple IP addresses, URLs, CIDR ranges, and ports. The

100
xonoxitron/regreSSHion

CVE-2024-6387 (regreSSHion) Exploit (PoC), a vulnerability in OpenSSH's server (sshd) on glibc-based Linux systems.

65
d0rb/CVE-2024-6387

This Python script exploits a remote code execution vulnerability (CVE-2024-6387) in OpenSSH.

49
bigb0x/CVE-2024-6387

Bulk Scanning Tool for OpenSSH CVE-2024-6387, CVE-2006-5051 , CVE-2008-4109 and others.

35
10 repos — triés par ⭐ Rechercher sur GitHub ↗

Signal Intelligence

Confidence
85%
EPSS 63.05%
CVSS v3.1 8.1
Mentions 6
Last Seen Jul 09, 2024

CNA Information

CNA Assigner
redhat
CNA Title
Openssh: regresshion - race condition in ssh allows rce/dos

Analyst Note

CVE-2024-6387 is the OpenSSH regreSSHion vulnerability (CVE-2024-6387), a critical remote code execution flaw. CERT-EU and CERT-FR security advisories from July 2024 confirm active exploitation in the wild. The vulnerability was exploited before and concurrent with patch availability, meeting zero-day criteria. Strong institutional validation from EU cybersecurity authorities supports confirmation despite limited article excerpt detail.

Threat Actors 2

Mana Team
apt_group 🇨🇳 CN
Dark Partners
apt_group

Triage Info

Decided atMar 05, 2026
Published DateJul 01, 2024