CiberLATAMbywhalemate

Chile alerts on OpenSSH CVE-2024-6387

CSIRT Chile warned about critical OpenSSH flaw CVE-2024-6387 and confirmed active exploitation. Patch or mitigate now.

Whalemate Labs · AI-assisted researchJul 26, 20262 min read

Chile’s government CSIRT issued a security advisory on the critical OpenSSH vulnerability CVE-2024-6387, known as regressh, and said public reports confirm active exploitation. The official guidance is to update to patched versions or apply configuration mitigations.

Official advisory in Chile

Chile’s government CSIRT published a security advisory on the critical OpenSSH vulnerability CVE-2024-6387, known as regressh. In its notice, the team said there is confirmed active exploitation based on public reports and urged organizations to take mitigation measures as soon as possible.

The official recommendation points to two paths, updating to patched versions or applying configuration mitigations. The Chilean alert joins other warnings issued by response teams and coordination bodies that have been tracking the issue since the flaw was disclosed.

What is known about the flaw

CVE-2024-6387 affects OpenSSH and was identified in the sshd component. The CERT Coordination Center reference itself describes it as a vulnerability in the sshd signal handler. OpenSSH included fixes in its 9.8 release notes, and the issue also appears in CISA’s Known Exploited Vulnerabilities catalog.

Qualys published a specific advisory on regressh, while Debian issued DSA-5706-1 with measures for its packages. The fact that the case appears in CISA’s KEV catalog reinforces that it is being tracked because of active exploitation.

Warnings across the region

Chile is not the only regional alert tied to OpenSSH. CERT-MX and CERT.br also issued advisories on CVE-2024-6387, aligned with the need to prioritize remediation in exposed environments.

The focus of these warnings is on servers and services that rely heavily on OpenSSH across critical and corporate infrastructure. In the materials available, the priority set by the agencies is the same, reduce exposure through updating or configuration mitigations while the risk remains.

Sources

View all