CVE-2024-6409 is a race condition vulnerability in OpenSSH's server component, sshd, affecting signal handling in the SIGALRM path. When an unauthenticated connection exceeds the configured login grace period, sshd invokes a SIGALRM handler asynchronously. That handler calls functions that are not async-signal-safe, including syslog(), creating a race condition that can corrupt process state during signal delivery. Under specific conditions, a remote unauthenticated attacker can exploit this flaw by sending specially crafted requests and timing interactions around the login timeout. In the worst case, successful exploitation may lead to remote code execution in the context of the unprivileged user running the sshd server. The issue was identified during follow-on analysis of the related OpenSSH signal-handler vulnerability CVE-2024-6387.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
OpenSSH remote code execution vulnerability involving a race condition in the privsep SIGALRM signal handler, discovered during follow-on analysis of CVE-2024-6387.
A newly disclosed OpenSSH server (sshd) vulnerability in glibc-based Linux systems involving a signal handler race condition.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.