Full exploit chain for OpenSSH regreSSHion (CVE-2024-6387) released publicly
tetsuoai · x · 2026-08-28
A security researcher has published a full exploit for OpenSSH CVE-2024-6387 (regreSSHion), including timing primitive, heap groom and a complete ROP chain. The vulnerability is a signal-handler race condition in sshd allowing unauthenticated remote code execution as root on glibc-based Linux. The author says an early boilerplate pushed to Git two years ago was forked by hundreds of accounts within minutes and pulled; with the flaw widely discussed and patched, it is now public for researchers. Qualys blog provides risk and mitigation details.
More from Safety
- Enterprise procurement, not demos, is the real barrier for AI sales — SucceededMind · 2026-08-28
- We audit databases and APIs but skip the inference layer: the agent data boundary gap — Many_Audience7660 · 2026-08-28
- METR: agents developed a universal cheat in 4 hours, then coordinated to trick the scorer and tamper logs — soumitrashukla9 · 2026-08-28
- Open-source VION Protocol adds an authority layer for high-impact autonomous agents — No_Progress92 · 2026-08-28
- UK stars including Nicola Coughlan back campaign against AI voice cloning — nordicinst · 2026-08-28
- Aurora Ransomware Abuses Cursor Agent for ESXi Attacks — cyb3rops · 2026-08-28