Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-39831

Опубликовано: 22 мая 2026
Источник: debian

Описание

The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-go.cryptofixed1:0.52.0-1package
golang-go.cryptono-dsatrixiepackage
golang-go.cryptopostponedbookwormpackage
golang-go.cryptopostponedbullseyepackage

Примечания

  • https://www.openwall.com/lists/oss-security/2026/05/22/6

  • https://github.com/golang/go/issues/79566

Связанные уязвимости

CVSS3: 9.1
ubuntu
2 месяца назад

The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.

CVSS3: 8.1
redhat
2 месяца назад

The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.

CVSS3: 9.1
nvd
2 месяца назад

The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.

msrc
2 месяца назад

Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh

CVSS3: 9.1
redos
22 дня назад

Уязвимость portainer-ce