Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-46598

Опубликовано: 22 мая 2026
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

For certain crafted inputs, a 'ed25519.PrivateKey' was created by casting malformed wire bytes, leading to a panic when used.

A flaw was found in golang.org/x/crypto/ssh/agent. An attacker could provide specially crafted inputs that, when processed, lead to the creation of an ed25519.PrivateKey by casting malformed wire bytes. This improper input handling can cause the program to panic and crash, resulting in a Denial of Service (DoS) for the affected component.

Отчет

A Moderate denial of service flaw exists in the golang.org/x/crypto/ssh/agent package. This vulnerability allows an attacker to provide specially crafted inputs that, when processed by the SSH agent, can lead to a program panic and crash. This could result in a temporary disruption of services that rely on the affected SSH agent functionality.

Меры по смягчению последствий

To mitigate this issue, restrict the exposure of the SSH agent to untrusted sources. Avoid enabling SSH agent forwarding when connecting to untrusted hosts or environments. Ensure that applications interacting with golang.org/x/crypto/ssh/agent validate all inputs to prevent malformed data from being processed. Reloading or restarting SSH services may be required for changes to take effect.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Assisted Installer for Red Hat OpenShift Container Platform 2assisted/agent-preinstall-image-builder-rhel9Fix deferred
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-controller-rhel9Fix deferred
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-git-cloner-rhel9Fix deferred
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-image-bundler-rhel9Fix deferred
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-image-processing-rhel9Fix deferred
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-waiters-rhel9Fix deferred
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-webhook-rhel9Fix deferred
External Secrets Operator for Red Hat OpenShiftexternal-secrets-operator/external-secrets-rhel9Fix deferred
Multicluster Engine for Kubernetesmulticluster-engine/cluster-image-set-controller-rhel9Fix deferred
Multicluster Engine for Kubernetesmulticluster-engine/hypershift-addon-rhel9-operatorUnder investigation

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1287
https://bugzilla.redhat.com/show_bug.cgi?id=2480679golang.org/x/crypto/ssh/agent: golang: golang.org/x/crypto/ssh/agent: Denial of Service via malformed input

EPSS

Процентиль: 34%
0.00412
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
2 месяца назад

For certain crafted inputs, a 'ed25519.PrivateKey' was created by casting malformed wire bytes, leading to a panic when used.

CVSS3: 5.3
nvd
2 месяца назад

For certain crafted inputs, a 'ed25519.PrivateKey' was created by casting malformed wire bytes, leading to a panic when used.

CVSS3: 5.3
msrc
2 месяца назад

Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent

CVSS3: 5.3
debian
2 месяца назад

For certain crafted inputs, a 'ed25519.PrivateKey' was created by cast ...

CVSS3: 5.3
github
около 1 месяца назад

golang.org/x/crypto: Invoking pathological inputs can lead to client panic

EPSS

Процентиль: 34%
0.00412
Низкий

5.3 Medium

CVSS3