[Midnightbsd-cvs] [MidnightBSD/src] fff0af: A signal handler in sshd(8) may call a logging fun...

Lucas Holt noreply at github.com
Thu Aug 8 18:12:48 EDT 2024


  Branch: refs/heads/master
  Home:   https://github.com/MidnightBSD/src
  Commit: fff0afc51b9137c07eb2ca4524e005bdb7f16746
      https://github.com/MidnightBSD/src/commit/fff0afc51b9137c07eb2ca4524e005bdb7f16746
  Author: Lucas Holt <luke at foolishgames.com>
  Date:   2024-08-08 (Thu, 08 Aug 2024)

  Changed paths:
    M crypto/openssh/sshd.c

  Log Message:
  -----------
  A signal handler in sshd(8) may call a logging function that is not async-
signal-safe.  The signal handler is invoked when a client does not
authenticate within the LoginGraceTime seconds (120 by default).  This signal
handler executes in the context of the sshd(8)'s privileged code, which is
not sandboxed and runs with full root privileges.

This issue is another instance of the problem in CVE-2024-6387 addressed by
FreeBSD-SA-24:04.openssh.  The faulty code in this case is from the
integration of blacklistd in OpenSSH

Obtained from: FreeBSD



To unsubscribe from these emails, change your notification settings at https://github.com/MidnightBSD/src/settings/notifications


More information about the Midnightbsd-cvs mailing list