Skip to content

CVE-2024-6387 #517

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
pkolega opened this issue May 18, 2025 · 1 comment
Open

CVE-2024-6387 #517

pkolega opened this issue May 18, 2025 · 1 comment

Comments

@pkolega
Copy link

pkolega commented May 18, 2025

Version of sshd (SSH-2.0-OpenSSH_9.6) is vulnerable. The vulnerability allows for remote code execution as root due to async-signal-unsafe functions being called in the SIGALRM handler.

@Krazy998
Copy link

Consider using the debian image as a base. I have been using this for months now and as its effectively a debian image. All normal security and base image updates are easily covered:
scpcom has provided a debian image for the nanokvm which works perfectly. (I think it makes sense at some point to move to this to make it easier to maintain)

https://github.com/scpcom/sophgo-sg200x-debian

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants