Описание
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| golang-go.crypto | fixed | 1:0.52.0-1 | package | |
| golang-go.crypto | no-dsa | trixie | package | |
| golang-go.crypto | postponed | bookworm | package | |
| golang-go.crypto | postponed | bullseye | package |
Примечания
https://www.openwall.com/lists/oss-security/2026/05/22/6
https://github.com/golang/go/issues/79561
EPSS
Процентиль: 40%
0.00473
Низкий
Связанные уязвимости
CVSS3: 7.5
ubuntu
4 месяца назад
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
CVSS3: 7.5
redhat
4 месяца назад
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
CVSS3: 7.5
nvd
4 месяца назад
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
CVSS3: 7.5
msrc
4 месяца назад
Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh
EPSS
Процентиль: 40%
0.00473
Низкий