CVE-2024-39894 is only about hidden text (ie: remote su or sudo) prompts, which doesn't sound particularly threatening.
CVE-2024-6387 is a potential RCE do to a race condition in Login Grace Timeout. This can be fixed set setting the value to 0 in sshd_config, which could cause other problems if you use SSH frequently.
The race condition is between sshd and Linux glibc syslog(), and may not be relevant for AIX. If you have anything on that, please post it.
https://www.ibm.com/support/pages/security-bulletin-aix-vulnerable-arbitrary-code-execution-cve-2024-6387-due-openssh
IBM posted a CVE for that, but only for 9.2.
Otherwise IBM is publishing (for unknown reasons) SSH updates on their MRS site: https://www.ibm.com/resources/mrs/assets/DirectDownload?source=aixbp&lang=en_US
9.7.3013.1000 is the latest they have there.
That's not really the AIX Open Source area, those are from IBM and not part of the AIX Toolkit.
------------------------------
========================
Russell Adams
https://adamssystems.nl/========================
------------------------------