Описание
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| golang-go.crypto | fixed | 1:0.52.0-1 | package | |
| golang-go.crypto | no-dsa | trixie | package | |
| golang-go.crypto | postponed | bookworm | package | |
| golang-go.crypto | postponed | bullseye | package |
Примечания
https://www.openwall.com/lists/oss-security/2026/05/22/6
https://github.com/golang/go/issues/79561
Связанные уязвимости
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh
golang.org/x/crypto: Invoking byte arithmetic causes underflow and panic