CVE-2026-39830
קריטית 9.1
תיאור (מקור, אנגלית)
A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now discarded.
מדדים
- CVSS 3.1
-
9.1 (CRITICAL)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H - EPSS — סבירות ניצול
- 1% (אחוזון 000) נכון ל-5/8/2026
- CWE
- CWE-119, CWE-772
מוצרים מושפעים
golang: crypto
קישורים
- https://pkg.go.dev/vuln/GO-2026-5017 Vendor Advisory
- https://go.dev/cl/781640 Issue Tracking
- https://go.dev/cl/781664 Issue Tracking
- https://go.dev/issue/79564 Issue Tracking
- https://groups.google.com/g/golang-announce/c/a082jnz-LvI Mailing List
- https://access.redhat.com/errata/RHSA-2026:29455
- https://access.redhat.com/errata/RHSA-2026:35833
- https://access.redhat.com/errata/RHSA-2026:36199
- https://access.redhat.com/errata/RHSA-2026:36207
- https://access.redhat.com/errata/RHSA-2026:36319