ssh-agent in OpenSSH before 8.5 contains a double-free memory management flaw. The issue is described as potentially relevant in less-common scenarios, including cases with unconstrained access to the agent socket on a legacy operating system, or when an SSH agent is forwarded to an attacker-controlled host. A successful trigger of the double free could lead to memory corruption.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Noregressh is a standalone Python penetration-testing toolkit centered on OpenSSH vulnerability discovery and exploitation workflows, especially CVE-2024-6387 (regreSSHion), with additional checks for CVE-2020-14145, CVE-2021-28041, CVE-2019-16905, and CVE-2018-15473. The repository contains 10 files, primarily Python modules: a launcher, menu/UI, core framework, scanner, exploit manager, listener manager, system checker, setup script, plus README and requirements. Repository structure and purpose: - no_regresh_launcher.py: simple startup wrapper that imports the menu system and launches the framework. - no_regresh_menu.py: interactive CLI front-end exposing scanner, exploitation, listener, system status, and log viewing workflows. - no_regresh_main.py: core framework utilities including logging, signal handling, banner display, SSH banner grabbing, and version-to-CVE matching logic. - no_regresh_scanner.py: multithreaded network scanner for IP ranges or single hosts, focused on SSH service discovery and banner-based vulnerability assessment, with export/report support. - no_regresh_exploit.py: exploit/payload module. It defines payload configuration/result structures and generates multiple shell payload variants (bash, Python, PowerShell, Perl, bind shell, shellcode stubs). It also includes post-exploitation helper routines for persistence, exfiltration prep, lateral movement prep, and cleanup steps. - no_regresh_listener.py: local listener subsystem implementing a Python TCP listener and management for active listeners, intended to receive reverse-shell connections and provide an interactive shell-like session. - no_regresh_system.py: environment validation and reporting, checking Python version, modules, tools, permissions, connectivity, firewall/AV status, and generating JSON system reports. - setup.py: installer/bootstrap script that installs Python dependencies, checks for external tools, optionally installs packages via apt/yum, creates directories, and prepares the environment. Main exploit capabilities: 1. Network reconnaissance: scans IP ranges with threading, probes SSH banners, and identifies likely vulnerable OpenSSH versions. 2. Vulnerability targeting: maps observed OpenSSH banners to supported CVEs and drives targeted workflows. 3. Payload generation: creates reverse-shell payloads for multiple interpreters and a Python bind-shell payload; includes base64-encoded bash and simple shellcode placeholders. 4. Listener operations: starts local listeners on configurable ports, defaulting to 0.0.0.0 and commonly 4444, to catch reverse connections. 5. Post-exploitation support: includes helper logic and operator guidance for file transfer, screenshots, keylogging, persistence, exfiltration, lateral movement, and cleanup. The code appears to be an operational offensive toolkit rather than a pure detector. However, based on the visible content, the vulnerability identification is largely banner/version based, and the actual exploit reliability for CVE-2024-6387 is not fully verifiable from the truncated excerpts. Still, the repository clearly contains exploit-oriented payload and listener functionality beyond simple detection.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.