CVE-2024-6409 is a race condition in OpenSSH sshd signal handling affecting the OpenSSH 8.7p1 and 8.8p1 packages shipped with Red Hat Enterprise Linux 9 and derived distributions. When an unauthenticated connection exceeds the configured authentication grace period, sshd asynchronously invokes a SIGALRM handler in the privilege-separation process. That handler calls functions that are not async-signal-safe, including logging functionality, creating a timing-dependent race condition. Carefully timed unauthenticated requests may corrupt process state and potentially permit code execution in the context of the unprivileged account used by the sshd privilege-separation process.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability addressed by the updated container image; the advisory provides no technical description.
A possible OpenSSH remote-code-execution vulnerability caused by a race condition in signal handling, affecting Red Hat Enterprise Linux 9.
A possible remote-code-execution vulnerability caused by a race condition in OpenSSH signal handling that affects Red Hat Enterprise Linux 9 and is remediated in this OpenShift update.
A vulnerability addressed by the OpenShift Container Platform 4.12.63 update; no technical description is provided in the content.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.