Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-12028

Опубликовано: 22 мая 2026
Источник: fstec
CVSS3: 7.5
CVSS2: 7.8
EPSS Низкий

Описание

Уязвимость функции Close() языка программирования Go связана с выходом операции за границы буфера в памяти. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, вызвать отказ в обслуживании

Вендор

Red Hat, Inc.
ООО «Ред Софт»
The Go Project

Наименование ПО

Red Hat Enterprise Linux
РЕД ОС
OpenShift API for Data Protection
Red Hat Quay
Red Hat Trusted Artifact Signer
Go
Red Hat Openshift Data Foundation
Red Hat Edge Manager
Red Hat OpenShift Builds

Версия ПО

8 (Red Hat Enterprise Linux)
9 (Red Hat Enterprise Linux)
10 (Red Hat Enterprise Linux)
8.8 Telecommunications Update Service (Red Hat Enterprise Linux)
8.8 Update Services for SAP Solutions (Red Hat Enterprise Linux)
8.0 (РЕД ОС)
1.3 (OpenShift API for Data Protection)
3.1 (Red Hat Quay)
3.12 (Red Hat Quay)
3.9 (Red Hat Quay)
3.15 (Red Hat Quay)
3.16 (Red Hat Quay)
1.3 (Red Hat Trusted Artifact Signer)
до 0.52.0 (Go)
1.4 (Red Hat Trusted Artifact Signer)
4.22 (Red Hat Openshift Data Foundation)
1.6 (OpenShift API for Data Protection)
1.0 (Red Hat Edge Manager)
1.1 (Red Hat Edge Manager)
1.8.1 (Red Hat OpenShift Builds)

Тип ПО

Операционная система
Прикладное ПО информационных систем

Операционные системы и аппаратные платформы

Red Hat, Inc. Red Hat Enterprise Linux 8
Red Hat, Inc. Red Hat Enterprise Linux 9
Red Hat, Inc. Red Hat Enterprise Linux 10
Red Hat, Inc. Red Hat Enterprise Linux 8.8 Telecommunications Update Service
Red Hat, Inc. Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
ООО «Ред Софт» РЕД ОС 8.0

Уровень опасности уязвимости

Высокий уровень опасности (базовая оценка CVSS 2.0 составляет 7,8)
Высокий уровень опасности (базовая оценка CVSS 3.1 составляет 7,5)

Возможные меры по устранению уязвимости

Использование рекомендаций производителя:
https://pkg.go.dev/vuln/GO-2026-5017
Для программных продуктов Red Hat Inc.:
https://access.redhat.com/security/cve/cve-2026-39830
Для Ред ОС:
http://repo.red-soft.ru/redos/8.0/x86_64/updates/

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 48%
0.00621
Низкий

7.5 High

CVSS3

7.8 High

CVSS2

Связанные уязвимости

CVSS3: 7.5
redos
15 дней назад

Уязвимость prometheus-podman-exporter

CVSS3: 9.1
ubuntu
4 месяца назад

A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now discarded.

CVSS3: 7.5
redhat
4 месяца назад

A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now discarded.

CVSS3: 9.1
nvd
4 месяца назад

A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now discarded.

CVSS3: 9.1
msrc
4 месяца назад

Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh

EPSS

Процентиль: 48%
0.00621
Низкий

7.5 High

CVSS3

7.8 High

CVSS2