CVE-2024-6387 - regreSSHion

The version and wording in the links are confusing to check if the fixed version is present.

From the blog post (AlmaLinux OS - Forever-Free Enterprise-Grade Operating System) we get these instructions:

Update the openssh package to protect your system against this issue:

sudo dnf --refresh upgrade openssh

Confirm the updated version. You are looking for openssh-8.7p1-38.el9.alma.2.

rpm -q openssh

That last command gives this output on my AlmaLinux install:
openssh-8.7p1-38.el9_4.1.x86_64

So it’s not openssh-8.7p1-38.el9.alma.2, so I need an update.

On the Errata page (ALSA-2024:4312) it says under Updated packages listed below:
x86_64 — openssh-8.7p1-38.el9_4.1.x86_64.rpm

So according to this I do have the fixed version. But when I check with ssh -V I get the following output:
OpenSSH_8.7p1, OpenSSL 3.0.7 1 Nov 2022
So it’s an old version.

This is confusing. In the end I found what version was installed with dnf history and dnf history info xxx but I suggest the Blogpost be adjusted to mention to not look for “alma.2” with the rpm -q openssh command if it doesn’t yield the correct results.