Bug 2480682 (CVE-2026-39827)

Summary: CVE-2026-39827 golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via repeated rejected channel openings
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: aazores, akhatavk, akoudelk, amctagga, anjoseph, aoconnor, aos-team-art-private, aruklets, asdas, bniver, cmah, crizzo, dakwon, dhanak, dkeler, doconnor, dpaolell, drosa, dsimansk, dymurray, eaguilar, ebaron, eborisov, eglynn, flucifre, gbenhaim, gmeno, gparvin, groman, jbalunas, jburrell, jdelft, jeder, jjoyce, jmatsuok, jmatthew, jolong, jprabhak, jpretori, jschluet, jtolenti, jupierce, kingland, lball, lbragsta, lgamliel, lgarciaa, lhh, manissin, mbenjamin, mbiarnes, mburns, mgarciac, mhackett, mnovotny, ngough, niyer, pjindal, ppalepu, ppostler, prdhamdh, rekumar, rhaigner, rhel-process-autobot, rjohnson, sausingh, sbratsla, sdawley, sghai, sidsharm, sostapov, suppawar, thason, tsze, twaugh, vereddy, veshanka, vkarehfa, vlaad, vvoronko, watson-tool-maintainers, wenshen, whayutin, wtam
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in golang.org/x/crypto/ssh. An authenticated SSH client can cause a Denial of Service (DoS) by repeatedly opening channels that are rejected by the server. This leads to unbounded memory growth, eventually crashing the server process and affecting all connected users.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-05-22 04:01:55 UTC
An authenticated SSH client that repeatedly opened channels which were rejected by the server caused unbounded memory growth, eventually crashing the server process and affecting all connected users. Rejected channels are now properly removed from the connection's internal state and released for garbage collection.