Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-78662

Опубликовано: 02 сент. 2026
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.

A flaw was found in golang.org/x/crypto/ssh. A malicious remote attacker could flood a channel's incoming requests before it is established, leading to a deadlock of the entire connection. This could result in a denial of service (DoS) for legitimate users.

Отчет

A malicious SSH peer can flood a channel with crafted requests before the channel is fully established, causing the affected SSH connection to become unresponsive. This vulnerability does not affect confidentiality or integrity. Red Hat rates this issue as Moderate because the demonstrated availability impact is limited to the affected connection.

Меры по смягчению последствий

Red Hat is not aware of a practical mitigation that fully prevents this issue while maintaining affected SSH functionality. Where operationally possible, restrict SSH connectivity to trusted systems. Apply relevant Red Hat updates when they become available.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Assisted Installer for Red Hat OpenShift Container Platform 2assisted/agent-preinstall-image-builder-rhel9Fix deferred
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-controller-rhel10Fix deferred
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-controller-rhel9Fix deferred
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-git-cloner-rhel10Fix deferred
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-git-cloner-rhel9Fix deferred
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-image-bundler-rhel10Fix deferred
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-image-bundler-rhel9Fix deferred
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-image-processing-rhel10Fix deferred
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-image-processing-rhel9Fix deferred
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-waiters-rhel10Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-833
https://bugzilla.redhat.com/show_bug.cgi?id=2528026golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via channel request flooding

EPSS

Процентиль: 24%
0.00315
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
15 дней назад

Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.

CVSS3: 7.5
nvd
15 дней назад

Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.

msrc
13 дней назад

Prevent DoS on deadlocked undecided channel in golang.org/x/crypto/ssh

CVSS3: 7.5
debian
15 дней назад

Previously, a channel registered in the mux's chanList is not usable u ...

suse-cvrf
3 дня назад

Security update for keybase-client

EPSS

Процентиль: 24%
0.00315
Низкий

5.3 Medium

CVSS3

Уязвимость CVE-2026-78662