Bug 2480683 (CVE-2026-39833)

Summary: CVE-2026-39833 golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to unenforced key confirmation
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: aazores, abuckta, agarcial, akostadi, akoudelk, alcohan, alebedev, alinfoot, amasferr, amctagga, anjoseph, anpicker, anthomas, aoconnor, aprice, aruklets, asegurap, asyoung, bdettelb, bniver, bparees, cahl, ckandaga, cmah, crizzo, dakwon, dbosanac, derez, dfreiber, dhanak, dkeler, dkuc, dmayorov, doconnor, drosa, drow, dschmidt, dsimansk, dtrifiro, dymurray, eaguilar, ebaron, eborisov, eglynn, ehelms, eshamard, fdeutsch, flucifre, ggainey, gmeno, gparvin, groman, gtanzill, hasun, ibolton, jbalunas, jburrell, jbuscemi, jcantril, jdobes, jfula, jhollowa, jjoyce, jkoehler, jlanda, jlledo, jmatthew, jmitchel, jmontleo, jolong, jowilson, jpasqual, jprabhak, jpretori, jreimann, jsamir, jschluet, jsherril, juwatts, jvasik, kaycoth, kbempah, kgaikwad, kingland, kshier, kverlaen, lball, lbragsta, lchilton, lgamliel, lhh, ljawale, lphiri, manissin, mbenjamin, mburns, mdessi, mgarciac, mhackett, mhulan, mkleinhe, mnovotny, mrizzi, msilmser, mstipich, mwringe, ngough, nmoumoul, nyancey, oezr, ometelka, orabin, oramraz, osousa, pahickey, pakotvan, pantinor, pcattana, pcreech, pgaikwad, pjindal, prichard, ptisnovs, pvasanth, rblanco, rbryant, rchan, rekumar, rexwhite, rfreiman, rhaigner, rhel-process-autobot, rjohnson, rochandr, rojacob, sakbas, sausingh, sbratsla, sdawley, sfeifer, simaishi, slucidi, smallamp, smullick, solenoci, sostapov, sseago, stcannon, sthirugn, stirabos, suppawar, syedriko, teagle, thason, tmalecek, tsedmik, tzivkovi, vereddy, veshanka, vkumar, vvoronko, watson-tool-maintainers, weaton, wenshen, whayutin, wtam, xdharmai, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in golang.org/x/crypto/ssh/agent. The NewKeyring() function, which creates an in-memory keyring, failed to enforce the ConfirmBeforeUse constraint on keys. This allowed keys configured to require user confirmation before use to perform signing operations without any prompt or indication to the user. Consequently, an attacker could potentially bypass intended security controls, leading to unauthorized cryptographic signing actions.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2494432, 2494433, 2494434, 2494435, 2494438, 2494439, 2494440, 2494442, 2494443, 2494444, 2494446, 2494447, 2494449, 2494450, 2494451, 2494453, 2494454, 2494455, 2494456, 2494458, 2494459, 2494460, 2494461, 2494462, 2494463, 2494464, 2494465, 2494466, 2494467, 2494468, 2494469, 2494470, 2494471, 2494473, 2494436, 2494437, 2494441, 2494445, 2494448, 2494452, 2494457, 2494472    
Bug Blocks:    

Description OSIDB Bzimport 2026-05-22 04:01:58 UTC
The in-memory keyring returned by NewKeyring() silently accepted keys with the ConfirmBeforeUse constraint but never enforced it. The key would sign without any confirmation prompt, with no indication to the caller that the constraint was not in effect. NewKeyring() now returns an error when unsupported constraints are requested.