Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-39830

Опубликовано: 22 мая 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now discarded.

A flaw was found in golang.org/x/crypto/ssh. A remote malicious SSH peer can exploit this by sending unsolicited global request responses, which fills an internal buffer and blocks the connection's read loop. This prevents the associated resources from being released, leading to a resource leak per connection. The consequence is a Denial of Service (DoS) for the affected system.

Отчет

This is an Important denial of service flaw in golang.org/x/crypto/ssh. A remote, unauthenticated attacker can exploit this vulnerability by sending unsolicited global request responses to an affected SSH server, leading to resource exhaustion and a denial of service. The impact is considered Important due to the potential for unauthenticated remote disruption of services utilizing the vulnerable SSH library.

Меры по смягчению последствий

To mitigate this denial of service vulnerability, restrict network access to any service that utilizes the golang.org/x/crypto/ssh library and is exposed to untrusted networks. Implement firewall rules to allow connections only from trusted hosts or networks. This action limits the ability of malicious peers to send unsolicited global request responses. A restart of the affected service may be necessary for the new network rules to be applied effectively.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Assisted Installer for Red Hat OpenShift Container Platform 2assisted/agent-preinstall-image-builder-rhel9Affected
Confidential Compute Attestationopenshift-sandboxed-containers/osc-cloud-api-adaptor-rhel9Affected
Confidential Compute Attestationopenshift-sandboxed-containers/osc-podvm-payload-rhel9Affected
Confidential Compute Attestationopenshift-sandboxed-containers/osc-rhel9-operatorAffected
External Secrets Operator for Red Hat OpenShiftexternal-secrets-operator/external-secrets-rhel9Will not fix
Multicluster Engine for Kubernetesmulticluster-engine/assisted-service-8-rhel8Affected
Multicluster Engine for Kubernetesmulticluster-engine/assisted-service-9-rhel9Affected
Multicluster Engine for Kubernetesmulticluster-engine/azure-service-operator-rhel9Affected
Multicluster Engine for Kubernetesmulticluster-engine/cluster-api-provider-azure-rhel9Affected
Multicluster Engine for Kubernetesmulticluster-engine/cluster-api-provider-kubevirt-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-772
https://bugzilla.redhat.com/show_bug.cgi?id=2480684golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses

EPSS

Процентиль: 47%
0.00621
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
3 месяца назад

A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now discarded.

CVSS3: 9.1
nvd
3 месяца назад

A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now discarded.

CVSS3: 9.1
msrc
3 месяца назад

Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh

CVSS3: 9.1
debian
3 месяца назад

A malicious SSH peer could send unsolicited global request responses t ...

CVSS3: 7.5
redos
около 1 месяца назад

Уязвимость portainer-ce

EPSS

Процентиль: 47%
0.00621
Низкий

7.5 High

CVSS3

Уязвимость CVE-2026-39830