A critical remote code execution vulnerability in OpenSSH, publicly disclosed on July 1st and known as regreSSHion (CVE-2024-6387), affects a range of OpenSSH server versions. Out of an abundance of caution we are scheduling expedited maintenance for the window of 2:00AM to 4:00AM EDT on Wednesday, July 3rd, 2024 to apply the patched OpenSSH packages across our entire fleet.
Our servers sit behind firewalling and access controls that already significantly reduce exposure, but patching promptly is the right thing to do. Applying the update requires a brief restart of the SSH service on each node; your websites, email, and databases are not affected by this and remain online throughout. The most you should witness is a momentary interruption to any active SSH/SFTP session, which can simply be reconnected.
No further action is required on your part. If you have any questions about this update or your account's security posture, we are available at support@xwebhosting.org.
Tirsdag, juli 2, 2024