PoC Archive PoC Archive

tag

Sshd

  • CVE-2026-7270 binary CRITICAL

    FreeBSD exec_args_adjust_args() Out-of-Bounds memmove — Local Privilege Escalation via sshd Race (CVE-2026-7270)

    An operator-precedence bug in FreeBSD's execargsadjustargs() (present since 2013) computes a memmove size using + consume instead of - consume, causing the copy length to be roughly double the correct value. With a ~265KB argv[0] supplied via a shebang exec,…

    Unverified 2026-07-05
  • CVE-2024-6387 network HIGH 8.1 EPSS 100%

    OpenSSH regreSSHion Signal-Handler Race Unauthenticated RCE (CVE-2024-6387)

    CVE-2024-6387 (regreSSHion) is a signal-handler race condition in OpenSSH sshd that reintroduced a previously fixed bug class and can allow unauthenticated remote code execution as root on glibc-based Linux systems. The issue is triggered around…

    Patched 2026-05-16