CVE-2024-39894

HIGH

OpenSSH 9.5-9.7 - Time-of-check Time-of-use Race Condition in ObscureKeystrokeTiming

Title source: llm
STIX 2.1

Description

OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sudo) because of an ObscureKeystrokeTiming logic error. Similarly, other timing attacks against keystroke entry could occur.

Scores

CVSS v3 7.5
EPSS 0.0148
EPSS Percentile 70.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-367
Status published
Published Jul 02, 2024
Tracked Since Feb 18, 2026