Hi All,
Openssh has a CVE
https://community.ipfire.org/t/cve-2024-6387-openssh-regession/11806
I am building a package update for Openssh to 9.8p1 and will submit to go into CU187.
I am not sure that it is super critical for IPFire as so far the exploit has only been demonstrated in 32 bit systems with the attacker having to try and make connections for 6 to 8 hours.
On 64 bit systems they expect it will take longer but so far the exploit has not yet been demonstrated.
Regards,
Adolf.