Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

This July 5, 2024 security roundup covered five different risks: a regression in OpenSSH’s SSH server, malicious JavaScript delivered through polyfill.io, a dispute over a Node.js package vulnerability, a Linux kernel use-after-free, and account-claiming flaws in CocoaPods. The most urgent lesson for server operators is to check their distribution’s OpenSSH package advisory—not just the upstream version number—and install the vendor-supported fix.

What regreSSHion meant for OpenSSH servers

CVE-2024-6387, nicknamed regreSSHion, was a regression of an older OpenSSH flaw, CVE-2006-5051. Qualys reported that unsafe behavior returned in OpenSSH 8.5p1: when a client failed to authenticate before LoginGraceTime expired, the sshd SIGALRM handler could call functions such as syslog(), which are not safe to call from an asynchronous signal handler. Under the conditions described by Qualys, that race could allow unauthenticated remote code execution as root on glibc-based Linux systems.

OpenSSH 9.8p1 fixed the upstream issue. OpenBSD was not vulnerable, according to the OpenSSH advisory, because its signal handler uses syslog_r(). The upstream affected range cited in that advisory was Portable OpenSSH 8.5p1 through 9.7p1; that range is a starting point for investigation, not a substitute for checking a vendor package.

How difficult was exploitation?

Qualys demonstrated exploitation in a Debian 12.5.0 i386 virtual machine over a mostly stable network with about 10 ms of packet jitter. In those test conditions, it reported an average of roughly 10,000 attempts to win the race and an average of about 6–8 hours to obtain a remote root shell. Those are results from that particular experiment, not a general estimate of how long an attack against any server would take. Qualys said exploitation on amd64 was harder because of stronger ASLR, and that its amd64 work was ongoing.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall

How to check whether OpenSSH is patched

Distributions often backport security fixes without changing a package’s upstream version in the way a simple version comparison might suggest. Check the package installed on the host against the security advisory for that exact distribution and release.

  1. Identify the host’s distribution and release. Use the system’s standard release information or administration interface; do not assume two machines with the same OpenSSH upstream version have the same patch status.
  2. Identify the installed server package. Check the package that provides sshd, commonly named openssh-server, using the distribution’s package manager.
  3. Compare it with the vendor’s CVE-2024-6387 advisory. Use the advisory for the machine’s specific release and architecture, including any release-specific notes or mitigations. Debian and Ubuntu publish package status by release; their listed fixed package versions can differ.
  4. Apply the vendor-supported update and confirm the resulting package status. Follow the distribution’s instructions, then check the installed package again. A version string that appears to fall in the upstream range does not by itself prove the distribution package remains vulnerable.

The Debian tracker cited for the roundup marked its listed Bookworm, Trixie, and Forky/Sid package versions fixed; it listed Bullseye as not affected because the vulnerable code was introduced later. Ubuntu listed fixed package versions for affected releases and noted that its Ubuntu 24.04 systemd socket-activation patch was believed to prevent the exploitation approach used by Qualys. Package status can change, so administrators should consult the current advisory for their installed release rather than rely on a historical status summary.

Why not set LoginGraceTime=0?

The OpenSSH advisory notes that setting LoginGraceTime=0 can prevent this attack, but it also makes denial-of-service attacks against sshd considerably easier. Treat it as a trade-off, not a routine substitute for applying a supported update.

What happened to polyfill.io?

The roundup reported that Funnull acquired the polyfill.io domain and GitHub account, after which the service delivered malicious scripts in place of the expected polyfill code. That matters because a site loading a third-party script is trusting not only the script’s code but also the people and systems that control its delivery.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Hackaday relayed a Sansec report that nearly 400,000 domains were still attempting to load polyfill.io as of July 3, 2024. That is a dated count, not a measure of how many sites are affected now. The column also reported that Google blocked associated domains from advertising, Cloudflare rewrote requests to a clean cache, and Namecheap blackholed the domain.

For site owners, the practical review is to find pages and build configurations that still reference polyfill.io, remove or replace those dependencies, and verify the scripts a page actually loads. A third-party service can become a supply-chain risk when its domain or account changes hands; a previously trusted URL is not a guarantee that the delivered code remains trustworthy.

Why the node-ip vulnerability score was disputed

The roundup discussed CVE-2023-42282 in the Node.js package node-ip. It reported an initial CVSS score of 9.8 and said GitHub later reduced the advisory severity to low. The package author disputed describing the issue as a vulnerability when exploitation required an application to pass untrusted input into the package and then rely on the result in an authorization check.

The disagreement is about the boundary between a library and the application using it. A package may process an address, but the security impact depends on whether an attacker can control that address and whether the consuming application trusts the result to make an access decision. A high score does not establish that every use of the package is exploitable; a lower score does not make every use safe.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Trace input control: Can an outside user influence the address passed into the package?
  • Inspect the decision point: Does the application use the result to allow or deny access, or for another security-sensitive decision?
  • Assess the consequence: What would happen if an invalid or unexpected address were treated as trusted?
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Two more issues in the roundup

Linux TIPC use-after-free

The TIPC item concerned a remote use-after-free in fragmentation error handling: the last fragment buffer could be freed twice. The roundup said the issue was fixed in Linux kernel 6.8 and noted that TIPC is not built into the kernel by default. Administrators should use their kernel vendor’s security status rather than infer exposure from the upstream version alone; whether TIPC is present and enabled also matters.

CocoaPods trunk account claiming

The CocoaPods issue involved trunk account-claiming vulnerabilities after a migration separated packages from their correct maintainer accounts. The roundup described the project’s disclosures as fixed in late 2023. This was a historical account of the disclosure and fix, not a statement about present-day service status.

What these incidents have in common

The five items point to different failure points: unsafe signal handling in a network service, changed control of a third-party script, an application trusting data from a library, memory management in kernel networking code, and package ownership during a service migration. The shared operational lesson is to verify the specific trust boundary and patch status that applies to your system, rather than treating a headline severity or a familiar software name as a complete risk assessment.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.