Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-42508

Опубликовано: 22 мая 2026
Источник: redhat
CVSS3: 7.4

Описание

Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.

A flaw was found in golang.org/x/crypto/ssh/knownhosts. This vulnerability occurs because the system did not correctly check for the revocation status of a SignatureKey belonging to a Certificate Authority (CA). A remote attacker could potentially exploit this by presenting a revoked key, leading to the system accepting it as valid. This could allow an attacker to bypass security checks and potentially gain unauthorized access or spoof legitimate entities.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Assisted Installer for Red Hat OpenShift Container Platform 2assisted/agent-preinstall-image-builder-rhel9Affected
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-waiters-rhel9Affected
External Secrets Operator for Red Hat OpenShiftexternal-secrets-operator/external-secrets-rhel9Affected
Multicluster Engine for Kubernetesmulticluster-engine/cluster-image-set-controller-rhel9Affected
OpenShift API for Data Protectionoadp/oadp-mustgather-rhel9Affected
OpenShift Serverlessopenshift-serverless-1/kn-plugin-func-func-util-rhel9Affected
OpenShift Serverlessopenshift-serverless-clientsAffected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/multicluster-operators-subscription-rhel9Affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/volsync-rhel9Will not fix
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-main-rhel8Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-295
https://bugzilla.redhat.com/show_bug.cgi?id=2480688golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
2 месяца назад

Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.

CVSS3: 9.1
nvd
2 месяца назад

Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.

CVSS3: 9.1
msrc
2 месяца назад

Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts

CVSS3: 9.1
debian
2 месяца назад

Previously, a revoked 'SignatureKey' belonging to a CA was not correct ...

CVSS3: 9.1
github
около 1 месяца назад

golang.org/x/crypto/ssh/knownhosts vulnerable to auth bypass via unenforced @revoked status

7.4 High

CVSS3