Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-46597

Опубликовано: 22 мая 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.

A flaw was found in golang.org/x/crypto/ssh. A remote attacker could send specially crafted inputs to the AES-GCM packet decoder. This could lead to an incorrectly placed cast from bytes to an integer, causing a server-side panic and resulting in a Denial of Service (DoS) for the affected system.

Отчет

This Important denial of service flaw in golang.org/x/crypto/ssh allows a remote attacker to trigger a server-side panic by sending specially crafted inputs to the AES-GCM packet decoder. This vulnerability could lead to service unavailability in Red Hat products that incorporate and expose SSH services built with the affected golang.org/x/crypto/ssh component.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Assisted Installer for Red Hat OpenShift Container Platform 2assisted/agent-preinstall-image-builder-rhel9Affected
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-controller-rhel9Affected
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-git-cloner-rhel9Affected
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-image-bundler-rhel9Affected
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-image-processing-rhel9Affected
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-waiters-rhel9Affected
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-webhook-rhel9Affected
cert-manager Operator for Red Hat OpenShiftcert-manager/jetstack-cert-manager-acmesolver-rhel9Affected
cert-manager Operator for Red Hat OpenShiftcert-manager/jetstack-cert-manager-rhel9Affected
Confidential Compute Attestationopenshift-sandboxed-containers/osc-cloud-api-adaptor-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-681
https://bugzilla.redhat.com/show_bug.cgi?id=2480678golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs

EPSS

Процентиль: 28%
0.00359
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
2 месяца назад

An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.

CVSS3: 7.5
nvd
2 месяца назад

An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.

CVSS3: 7.5
msrc
2 месяца назад

Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh

CVSS3: 7.5
debian
2 месяца назад

An incorrectly placed cast from bytes to int allowed for server-side p ...

CVSS3: 7.5
github
около 1 месяца назад

golang.org/x/crypto: Invoking byte arithmetic causes underflow and panic

EPSS

Процентиль: 28%
0.00359
Низкий

7.5 High

CVSS3