CVE-2024-6387

Executive Summary

CVE-2024-6387 is a race condition in OpenSSH's sshd that can cause unsafe signal handling when authentication fails within a timeout. An unauthenticated remote attacker can trigger the flaw, potentially leading to denial of service or other unintended behavior. The issue is a regression of CVE-2006-5051 and is not yet listed in CISA KEV.


Authoritative CVE Metadata - CVSS Base Score: 8.1 (HIGH) - Published: 2024-07-01T13:15:06.467 - Last Modified: 2026-08-31T17:17:32.007

Original Description: A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.

"It is the mark of an educated mind to be able to entertain a thought without accepting it."

— Aristotle
Source: NVD