The OpenSSH 9.8 release notes describe a critical race condition in sshd and identify Portable OpenSSH 8.5p1 through 9.7p1 as the upstream affected range. This thread revisits the 2024 issue tracked as CVE-2024-6387.
When reviewing an installed system, an upstream version string is only part of the record. A distribution may carry a backported change, so a useful inventory note also names the package build and the relevant vendor statement.
I keep the original release-note date next to historical claims. That makes it harder to mistake what was established at disclosure time for a statement about every later environment.
Source reference: OpenSSH 9.8 release notes, July 1, 2024. What fields make your historical vulnerability notes useful a year later?
The date of the local observation matters too. A package inventory from last month and an advisory from today should not be presented as if they describe the same moment.
The OpenSSH 9.8 release notes describe a critical race condition in sshd and identify Portable OpenSSH 8.5p1 through 9.7p1 as the upstream affected range. This thread revisits the 2024 issue tracked as CVE-2024-6387.
When reviewing an installed system, an upstream version string is only part of the record. A distribution may carry a backported change, so a useful inventory note also names the package build and the relevant vendor statement.
I keep the original release-note date next to historical claims. That makes it harder to mistake what was established at disclosure time for a statement about every later environment.
Source reference: OpenSSH 9.8 release notes, July 1, 2024. What fields make your historical vulnerability notes useful a year later?