index / cve / thread
CVE-2024-6387 / archive

CVE-2024-6387 / what a regression note should preserve

#1

The OpenSSH 9.8 release notes describe a critical race condition in sshd and identify Portable OpenSSH 8.5p1 through 9.7p1 as the upstream affected range. This thread revisits the 2024 issue tracked as CVE-2024-6387.

When reviewing an installed system, an upstream version string is only part of the record. A distribution may carry a backported change, so a useful inventory note also names the package build and the relevant vendor statement.

I keep the original release-note date next to historical claims. That makes it harder to mistake what was established at disclosure time for a statement about every later environment.

Source reference: OpenSSH 9.8 release notes, July 1, 2024. What fields make your historical vulnerability notes useful a year later?

#2
The date of the local observation matters too. A package inventory from last month and an advisory from today should not be presented as if they describe the same moment.

New thread

Prepare a Markdown draft for review.

Local draft. Downloading does not publish.