Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-32283

Опубликовано: 08 апр. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.

A flaw was found in the crypto/tls package within the Go (golang) standard library, specifically affecting TLS 1.3 connections. A remote attacker can exploit this vulnerability by sending multiple key update messages in a single record after the handshake. This can cause the connection to deadlock, leading to uncontrolled consumption of resources and ultimately a denial of service (DoS).

Отчет

Important: A flaw in the Go crypto/tls package allows a remote attacker to cause a denial of service in applications using TLS 1.3. By sending multiple key update messages in a single record post-handshake, an attacker can trigger a connection deadlock, leading to uncontrolled resource consumption. This impacts Red Hat products utilizing the affected Go standard library for TLS 1.3 connections.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Assisted Installer for Red Hat OpenShift Container Platform 2rhai/assisted-installer-rhel9Affected
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-waiters-rhel9Affected
cert-manager Operator for Red Hat OpenShiftcert-manager/jetstack-cert-manager-rhel9Affected
Confidential Compute Attestationbuild-of-trustee/trustee-rhel9-operatorAffected
Confidential Compute Attestationopenshift-sandboxed-containers/osc-monitor-rhel9Affected
Deployment Validation Operatordvo/deployment-validation-rhel8-operatorAffected
ExternalDNS Operatoredo/external-dns-rhel8Affected
ExternalDNS Operatoredo/external-dns-rhel9Not affected
External Secrets Operator for Red Hat OpenShiftexternal-secrets-operator/external-secrets-rhel9Will not fix
Fence Agents Remediation Operatorworkload-availability/fence-agents-remediation-rhel8-operatorAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-764
https://bugzilla.redhat.com/show_bug.cgi?id=2456338crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages

EPSS

Процентиль: 46%
0.00621
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.

CVSS3: 7.5
nvd
4 месяца назад

If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.

msrc
4 месяца назад

Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls

CVSS3: 7.5
debian
4 месяца назад

If one side of the TLS connection sends multiple key update messages p ...

rocky
2 месяца назад

Important: go-fdo-client security update

EPSS

Процентиль: 46%
0.00621
Низкий

7.5 High

CVSS3

Уязвимость CVE-2026-32283