
Automated bash script to patch CVE-2024-6387 by compiling and installing OpenSSH 9.8p1 from source on Debian/Ubuntu systems.
Only affects 8.5p1 <= OpenSSH < 9.8p1
sudo apt-get update
sudo apt-get install -y build-essential zlib1g-dev libssl-dev
wget https://cdn.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-9.8p1.tar.gz
tar -xzf openssh-9.8p1.tar.gz
cd openssh-9.8p1
./configure
make
sudo make install
sudo systemctl restart ssh
ssh -V
Complete fix script saved as fix.sh chmod 777 fix.sh | ./fix.sh
#!/bin/bash
# Update package list
echo "Updating package list..."
sudo apt-get update
# Install build dependencies
echo "Installing build dependencies..."
sudo apt-get install -y build-essential zlib1g-dev libssl-dev
# Download specified version source code
echo "Downloading OpenSSH 9.8p1 source code..."
wget https://cdn.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-9.8p1.tar.gz
# Extract and enter directory
echo "Extracting OpenSSH 9.8p1 source code..."
tar -xzf openssh-9.8p1.tar.gz
cd openssh-9.8p1
# Compile and install
echo "Compiling and installing OpenSSH 9.8p1..."
./configure
make
sudo make install
# Start and verify installation
echo "Restarting SSH service and verifying installation..."
sudo systemctl restart ssh
ssh -V
echo "OpenSSH 9.8p1 installation completed and successfully started. -By muyuanhuck.cn"