vendor:
OpenSSH server
by:
Milad Karimi (Ex3ptionaL)
6.1
CVSS
HIGH
Race Condition
362
CWE
Product Name: OpenSSH server
Affected Version From: 9.8p1
Affected Version To: 9.8p1
Patch Exists: NO
Related CWE:
CPE: a:openssh:openssh:9.8p1
Platforms Tested: Linux
2025
OpenSSH server (sshd) 9.8p1 – Race Condition
This exploit targets a race condition in the signal handler of OpenSSH's server (sshd) specifically on glibc-based Linux systems. By exploiting a vulnerability where the SIGALRM handler invokes async-signal-unsafe functions, it allows for remote code execution as root.
Mitigation:
To mitigate this vulnerability, it is recommended to update OpenSSH to a non-vulnerable version and regularly patch the system to address any potential security risks.