this post was submitted on 11 Jul 2024
23 points (100.0% liked)

Cybersecurity

5278 readers
315 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected]

Notable mention to [email protected]

founded 1 year ago
MODERATORS
top 4 comments
sorted by: hot top controversial new old
[–] [email protected] 9 points 1 month ago* (last edited 1 month ago) (1 children)

The CVE-2024-6409 vulnerability affects only the sshd server shipped in RHEL 9, while the upstream versions of sshd are not impacted.

Yes, only RHEL based releases affected (source):

Specifically, openssh-7.6p1-audit.patch found in Red Hat's package of OpenSSH adds code to cleanup_exit() that exposes the issue. Relevantly, this patch is found in RHEL 9 (and its rebuild/downstream distributions), where the package is based on OpenSSH 8.7p1.

Debian oldstable is safe from this as well

[–] sugar_in_your_tea 3 points 1 month ago

Looks like openSUSE Leap is fine, not sure about other SUSE distros.

[–] [email protected] -4 points 1 month ago (1 children)

Flashback xz package in linux getting louder and louder

[–] [email protected] 8 points 1 month ago

xz was a deliberate supply chain attack this is just a bug, accidental, not a rhel backdoor