# OpenSSH vulnerability CVE-2024-6387

**URL:** <https://forums.rockylinux.org/t/openssh-vulnerability-cve-2024-6387/14883>\
**Category:** Rocky Linux Help & Support\
**Created:** [July 1, 2024, 8:53pm UTC](https://forums.rockylinux.org/t/openssh-vulnerability-cve-2024-6387/14883 "2024-07-01T20:53:46Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![label](https://avatars.discourse-cdn.com/v4/letter/l/c5a1d2/32.png) [@label](https://forums.rockylinux.org/u/label)\
**Post date:** [July 1, 2024, 8:56pm UTC](https://forums.rockylinux.org/t/openssh-vulnerability-cve-2024-6387/14883/2 "2024-07-01T20:56:52Z")

</div>

We are aware. You have two options:

- Mitigate the issue by setting LoginGraceTime to 0 (note this can lead to a DoS)
- Install rocky-release-security and update openssh, as it contains a patch _until_ RHEL releases it themselves

See for more information: [cve-details](https://access.redhat.com/security/cve/CVE-2024-6387)

---

_[View the full topic](https://forums.rockylinux.org/t/openssh-vulnerability-cve-2024-6387/14883)._
