<?xml version="1.0" encoding="UTF-8"?>

<!-- AUTOGENERATED FILE. DO NOT EDIT. -->

<feed xmlns="http://www.w3.org/2005/Atom">
  <id>tag:google.com,2016:bare-metal-solution-security-bulletins</id>
  <title>Bare Metal Solution - Security Bulletins</title>
  <link rel="self" href="https://cloud.google.com/feeds/bare-metal-solution-security-bulletins.xml"/>
  <author>
    <name>Google Cloud</name>
  </author>
  <updated>2024-07-02T11:08:36.525602+00:00</updated>


  <entry>
    <title>GCP-2024-040</title>
    <id>tag:google.com,2016:bare-metal-solution-security-bulletins#gcp-2024-040</id>
    <updated>2024-07-02T11:08:36.525602+00:00</updated>
    <link rel="alternate" href="https://cloud.google.com/bare-metal/docs/security-bulletins#gcp-2024-040"/>
    <content type="html"><![CDATA[<p><strong>Published: </strong>2024-07-02</p><table>
<thead>
<tr>
<th width="75%">Description</th>
<th width="5%">Severity</th>
<th width="20%">Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td><p>A vulnerability CVE-2024-6387 was discovered in OpenSSH server (sshd). This vulnerability is exploitable remotely on glibc-based linux systems: an unauthenticated remote code execution as root, because it affects sshd's privileged code, which is not sandboxed and runs with full privileges. <br/><br/> At the time of publication, exploitation is believed to be difficult–requiring winning a race condition, which is hard to successfully exploit and may take several hours per machine being attacked.</p> <h4 data-text="Bare Metal Solution impact" id="bare-metal-solution-impact" tabindex="-1">Bare Metal Solution impact</h4> <p>Based on our investigations, we are not aware of any exploitation attempts on existing Google managed Bare Metal Solution infrastructure.</p> <h4 data-text="What should I do?" id="what-should-i-do" tabindex="-1">What should I do?</h4> <ol><li>We recommend updating to the safe OpenSSH version 9.8p1 once it is released, or applying sshd patches once provided by OS vendors.</li> <li>We also recommend disabling/removing vulnerable OpenSSH server wherever it is not required.</li> <li>Setup firewall rules to restrict access to SSH servers from trusted network endpoints.</li> <li>Monitor for any unusual network activity involving SSH servers.</li></ol></td>
<td>Critical</td>
<td><ul><li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-6387">CVE-2024-6387</a></li></ul></td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>


</feed>
