vmware / photon

Minimal Linux container host
https://vmware.github.io/photon
Other
3.04k stars 698 forks source link

Confirm security fix for CVE-2024-6387 #1560

Closed tracylv closed 2 months ago

tracylv commented 3 months ago

Describe the bug

Confirm security fix for CVE-2024-6387, I didn't find a maintainers email address, so file this ticket instead. please help forward to right team. Thanks!

Reproduction steps

For recent vulnerability ['CVE-2024-6387'], according to Photon OS Security Update, that is fixed in both 5.0 and 4.0 with package update per my understanding.

Expected behavior

Take photon 5 for example, below is the openssh version from our product, which consume photon OS, want to double confirm whether this version (9.3p2-9.ph5) include the remediation for CVE-2024-6387 or not. image image

Additional context

No response

akaher commented 3 months ago

openssh-9.3p2-9.ph5.x86_64.rpm includes the fix for CVE-2024-6387.

tracylv commented 3 months ago

Thanks @akaher !