CVE-2024-6387
Check your servers !!
- Affected Versions: OpenSSH 8.5p1 to 9.8p1.
- Exploit: Remote code execution as root due to the vulnerable SIGALRM handler calling async-signal-unsafe functions.
Also a reminder to not expose SSH to the world but only to a jump server. Workaround is available by setting LoginGraceTime to 0 in /etc/ssh/sshd_config.