Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-58181

Опубликовано: 19 нояб. 2025
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.

A flaw was found in golang.org/x/crypto/ssh. An attacker can exploit this vulnerability by sending specially crafted GSSAPI (Generic Security Service Application Program Interface) authentication requests to an SSH (Secure Shell) server. The server fails to validate the number of mechanisms specified in these requests, leading to unbounded memory consumption. This can result in a Denial of Service (DoS), making the SSH server unavailable to legitimate users.

Отчет

This vulnerability is rated Moderate for Red Hat. SSH servers utilizing golang.org/x/crypto/ssh and configured to process GSSAPI authentication requests are susceptible to unbounded memory consumption. An attacker can exploit this by sending specially crafted GSSAPI authentication requests, potentially leading to a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-controller-rhel9Under investigation
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-git-cloner-rhel9Under investigation
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-image-bundler-rhel9Under investigation
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-image-processing-rhel9Under investigation
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-waiters-rhel9Under investigation
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-webhook-rhel9Under investigation
cert-manager Operator for Red Hat OpenShiftcert-manager/jetstack-cert-manager-acmesolver-rhel9Under investigation
cert-manager Operator for Red Hat OpenShiftcert-manager/jetstack-cert-manager-rhel9Under investigation
Cryostat 4cryostat/cryostat-grafana-dashboard-rhel9Under investigation
Cryostat 4cryostat/cryostat-storage-rhel9Under investigation

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2415997golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via unbounded memory consumption in GSSAPI authentication

EPSS

Процентиль: 25%
0.00087
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
4 месяца назад

SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.

CVSS3: 5.3
nvd
4 месяца назад

SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.

CVSS3: 5.3
debian
4 месяца назад

SSH servers parsing GSSAPI authentication requests do not validate the ...

suse-cvrf
около 1 месяца назад

Security update for docker

suse-cvrf
24 дня назад

Security update for docker

EPSS

Процентиль: 25%
0.00087
Низкий

5.3 Medium

CVSS3