Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-39828

Опубликовано: 22 мая 2026
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently discarded, potentially dropping certificate restrictions such as force-command after a second factor succeeded. Returning non-nil Permissions with PartialSuccessError now results in a connection error.

A flaw was found in golang.org/x/crypto/ssh. A remote attacker could exploit this vulnerability when an SSH server authentication callback returned a PartialSuccessError with non-nil permissions. This flaw caused these permissions to be silently discarded, potentially bypassing certificate restrictions, such as a force-command, after a second authentication factor succeeded. This could lead to unauthorized command execution or access.

Отчет

This is an Important security flaw in the golang.org/x/crypto/ssh library. When an SSH server utilizing this library is configured with specific authentication callbacks that return a PartialSuccessError with non-nil permissions, an attacker could bypass intended certificate restrictions, such as force-command. This bypass could lead to unauthorized command execution or access on affected Red Hat systems configured with multi-factor authentication and certificate-based access controls.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Assisted Installer for Red Hat OpenShift Container Platform 2assisted/agent-preinstall-image-builder-rhel9Affected
cert-manager Operator for Red Hat OpenShiftcert-manager/jetstack-cert-manager-acmesolver-rhel9Affected
cert-manager Operator for Red Hat OpenShiftcert-manager/jetstack-cert-manager-rhel9Affected
Confidential Compute Attestationopenshift-sandboxed-containers/osc-cloud-api-adaptor-rhel9Affected
Confidential Compute Attestationopenshift-sandboxed-containers/osc-podvm-payload-rhel9Affected
Confidential Compute Attestationopenshift-sandboxed-containers/osc-rhel9-operatorAffected
External Secrets Operator for Red Hat OpenShiftexternal-secrets-operator/external-secrets-rhel9Will not fix
Multicluster Engine for Kubernetesmulticluster-engine/azure-service-operator-rhel9Affected
Multicluster Engine for Kubernetesmulticluster-engine/cluster-api-provider-azure-rhel9Affected
Multicluster Engine for Kubernetesmulticluster-engine/cluster-api-provider-kubevirt-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-281
https://bugzilla.redhat.com/show_bug.cgi?id=2480687golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions

EPSS

Процентиль: 30%
0.00369
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 6.3
ubuntu
3 месяца назад

When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently discarded, potentially dropping certificate restrictions such as force-command after a second factor succeeded. Returning non-nil Permissions with PartialSuccessError now results in a connection error.

CVSS3: 6.3
nvd
3 месяца назад

When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently discarded, potentially dropping certificate restrictions such as force-command after a second factor succeeded. Returning non-nil Permissions with PartialSuccessError now results in a connection error.

CVSS3: 6.3
msrc
2 месяца назад

Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh

CVSS3: 6.3
debian
3 месяца назад

When an SSH server authentication callback returned PartialSuccessErro ...

CVSS3: 6.3
github
около 1 месяца назад

golang.org/x/crypto vulnerable to invoking bypass of certificate restrictions

EPSS

Процентиль: 30%
0.00369
Низкий

8.8 High

CVSS3