CVE-2024-6387: NixOS vulnerability analysis and mitigation
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.
Source: NVD
Related NixOS vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploit
Has fix
Published date
CVE-2025-14330
CRITICAL
9.8
NixOS
cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
No
Yes
Dec 09, 2025
CVE-2025-14329
HIGH
8.8
NixOS
cpe:2.3:a:mozilla:firefox_esr
No
Yes
Dec 09, 2025
CVE-2025-14333
HIGH
8.1
NixOS
firefox-esr
No
Yes
Dec 09, 2025
CVE-2025-14332
HIGH
7.3
NixOS
thunderbird
No
Yes
Dec 09, 2025
CVE-2025-14331
MEDIUM
6.5
NixOS
firefox
No
Yes
Dec 09, 2025
Free Vulnerability Assessment
Benchmark your Cloud Security Posture
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.