Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-58181

Опубликовано: 19 нояб. 2025
Источник: debian

Описание

SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-go.cryptofixed1:0.45.0-1package
golang-go.cryptono-dsatrixiepackage
golang-go.cryptono-dsabookwormpackage
golang-go.cryptopostponedbullseyepackage

Примечания

  • https://groups.google.com/g/golang-announce/c/w-oX3UxNcZA?pli=1

  • https://github.com/golang/go/issues/76363

  • Fixed by: https://github.com/golang/crypto/commit/e79546e28b85ea53dd37afe1c4102746ef553b9c (v0.45.0)

Связанные уязвимости

CVSS3: 5.3
ubuntu
4 месяца назад

SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.

CVSS3: 5.3
redhat
4 месяца назад

SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.

CVSS3: 5.3
nvd
4 месяца назад

SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.

suse-cvrf
около 1 месяца назад

Security update for docker

suse-cvrf
24 дня назад

Security update for docker