Bug 2480683 (CVE-2026-39833)
| Summary: | CVE-2026-39833 golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to unenforced key confirmation | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | aazores, abuckta, agarcial, akostadi, akoudelk, alcohan, alebedev, alinfoot, amasferr, amctagga, anjoseph, anpicker, anthomas, aoconnor, aprice, aruklets, asegurap, asyoung, bdettelb, bniver, bparees, cahl, ckandaga, cmah, crizzo, dakwon, dbosanac, derez, dfreiber, dhanak, dkeler, dkuc, dmayorov, doconnor, drosa, drow, dschmidt, dsimansk, dtrifiro, dymurray, eaguilar, ebaron, eborisov, eglynn, ehelms, eshamard, fdeutsch, flucifre, ggainey, gmeno, gparvin, groman, gtanzill, hasun, ibolton, jbalunas, jburrell, jbuscemi, jcantril, jdobes, jfula, jhollowa, jjoyce, jkoehler, jlanda, jlledo, jmatthew, jmitchel, jmontleo, jolong, jowilson, jpasqual, jprabhak, jpretori, jreimann, jsamir, jschluet, jsherril, juwatts, jvasik, kaycoth, kbempah, kgaikwad, kingland, kshier, kverlaen, lball, lbragsta, lchilton, lgamliel, lhh, ljawale, lphiri, manissin, mbenjamin, mburns, mdessi, mgarciac, mhackett, mhulan, mkleinhe, mnovotny, mrizzi, msilmser, mstipich, mwringe, ngough, nmoumoul, nyancey, oezr, ometelka, orabin, oramraz, osousa, pahickey, pakotvan, pantinor, pcattana, pcreech, pgaikwad, pjindal, prichard, ptisnovs, pvasanth, rblanco, rbryant, rchan, rekumar, rexwhite, rfreiman, rhaigner, rhel-process-autobot, rjohnson, rochandr, rojacob, sakbas, sausingh, sbratsla, sdawley, sfeifer, simaishi, slucidi, smallamp, smullick, solenoci, sostapov, sseago, stcannon, sthirugn, stirabos, suppawar, syedriko, teagle, thason, tmalecek, tsedmik, tzivkovi, vereddy, veshanka, vkumar, vvoronko, watson-tool-maintainers, weaton, wenshen, whayutin, wtam, xdharmai, yguenane |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in golang.org/x/crypto/ssh/agent. The NewKeyring() function, which creates an in-memory keyring, failed to enforce the ConfirmBeforeUse constraint on keys. This allowed keys configured to require user confirmation before use to perform signing operations without any prompt or indication to the user. Consequently, an attacker could potentially bypass intended security controls, leading to unauthorized cryptographic signing actions.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2494432, 2494433, 2494434, 2494435, 2494438, 2494439, 2494440, 2494442, 2494443, 2494444, 2494446, 2494447, 2494449, 2494450, 2494451, 2494453, 2494454, 2494455, 2494456, 2494458, 2494459, 2494460, 2494461, 2494462, 2494463, 2494464, 2494465, 2494466, 2494467, 2494468, 2494469, 2494470, 2494471, 2494473, 2494436, 2494437, 2494441, 2494445, 2494448, 2494452, 2494457, 2494472 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-05-22 04:01:58 UTC
|