[Midnightbsd-cvs] [MidnightBSD/src] fff0af: A signal handler in sshd(8) may call a logging fun...
Lucas Holt
noreply at github.com
Thu Aug 8 18:12:48 EDT 2024
Branch: refs/heads/master
Home: https://github.com/MidnightBSD/src
Commit: fff0afc51b9137c07eb2ca4524e005bdb7f16746
https://github.com/MidnightBSD/src/commit/fff0afc51b9137c07eb2ca4524e005bdb7f16746
Author: Lucas Holt <luke at foolishgames.com>
Date: 2024-08-08 (Thu, 08 Aug 2024)
Changed paths:
M crypto/openssh/sshd.c
Log Message:
-----------
A signal handler in sshd(8) may call a logging function that is not async-
signal-safe. The signal handler is invoked when a client does not
authenticate within the LoginGraceTime seconds (120 by default). This signal
handler executes in the context of the sshd(8)'s privileged code, which is
not sandboxed and runs with full root privileges.
This issue is another instance of the problem in CVE-2024-6387 addressed by
FreeBSD-SA-24:04.openssh. The faulty code in this case is from the
integration of blacklistd in OpenSSH
Obtained from: FreeBSD
To unsubscribe from these emails, change your notification settings at https://github.com/MidnightBSD/src/settings/notifications
More information about the Midnightbsd-cvs
mailing list