Update your opensshd right the fuck now.
Conversation
Notices
-
Embed this notice
BSD/r000t (r000t@ligma.pro)'s status on Monday, 01-Jul-2024 21:20:35 JST BSD/r000t - Pleroma-tan likes this.
-
Embed this notice
Pleroma-tan (kirby@lab.nyanide.com)'s status on Monday, 01-Jul-2024 21:20:50 JST Pleroma-tan @r000t unironic +1 -
Embed this notice
翠星石 (suiseiseki@freesoftwareextremist.com)'s status on Monday, 01-Jul-2024 22:16:20 JST 翠星石 @r000t Provided your GNU/Linux system is 64-bit and has ALSR enabled, there's a good chance your system would take years to exploit, so you can update openssh a bit later if you don't mind risking it.
The bug existed for quite a while and there doesn't seem to be any cases of reported exploitation. -
Embed this notice
vic (vic@seal.cafe)'s status on Monday, 01-Jul-2024 22:56:32 JST vic @kirby @r000t Rule 1 in vulnerabilities: when it gets its own name and logo, it's a Big Deal. When it gets its own website, it's a Very Big Deal. Pleroma-tan likes this.