Release of OpenSSH 9.8p1 with a vulnerability fix

A vulnerability has been found in OpenSSH that allows remote code execution with root privileges without authentication. Only Linux servers using glibc and OpenSSH versions from 8.5p1 to 9.7p1 are affected. The issue lies in a race condition in signal handlers.

The attack has so far only been demonstrated in laboratory conditions on 32-bit systems and takes about 6-8 hours. 64-bit systems are theoretically also vulnerable, but due to the significantly larger address space used for ASLR, exploitation has not yet been possible.

Systems with other implementations of libc may also be vulnerable. OpenBSD still remains a bastion of security.

Source: linux.org.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster