Bug 2480684 (CVE-2026-39830)
| Summary: | CVE-2026-39830 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | aazores, akoudelk, alcohan, amctagga, anjoseph, aoconnor, aruklets, bdettelb, bniver, cmah, crizzo, dakwon, dhanak, dkeler, doconnor, drosa, dsimansk, dymurray, eaguilar, ebaron, eborisov, eglynn, fdeutsch, flucifre, gmeno, gparvin, groman, jaharrin, jbalunas, jburrell, jeder, jjoyce, jkoehler, jmatthew, jolong, jprabhak, jpretori, jschluet, kingland, kverlaen, lball, lbragsta, lgamliel, lhh, lphiri, manissin, mbenjamin, mburns, mgarciac, mhackett, mnovotny, ngough, oramraz, pahickey, pjindal, rekumar, rfreiman, rhaigner, rhel-process-autobot, rjohnson, sausingh, sbratsla, sdawley, smullick, sostapov, stirabos, suppawar, thason, vereddy, veshanka, vkarehfa, vvoronko, watson-tool-maintainers, wenshen, whayutin, wtam, xiyuan |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in golang.org/x/crypto/ssh. A remote malicious SSH peer can exploit this by sending unsolicited global request responses, which fills an internal buffer and blocks the connection's read loop. This prevents the associated resources from being released, leading to a resource leak per connection. The consequence is a Denial of Service (DoS) for the affected system.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2490391, 2490393, 2490394, 2490395, 2490398, 2490401, 2490404, 2490407, 2490410, 2490411, 2490414, 2490415, 2490417, 2490418, 2490419, 2490421, 2490423, 2490424, 2490425, 2490427, 2490428, 2490429, 2490432, 2490433, 2490434, 2490435, 2490436, 2490438, 2490440, 2490443, 2490444, 2490445, 2490446, 2490448, 2490451, 2490452, 2490453, 2490454, 2490457, 2490459, 2490460, 2490462, 2490467, 2490469, 2490470, 2490471, 2490472, 2490473, 2490475, 2490476, 2490477, 2490480, 2490481, 2490482, 2490483, 2490484, 2490485, 2490487, 2490491, 2490492, 2490493, 2490494, 2490495, 2490496, 2490499, 2490500, 2490501, 2490392, 2490396, 2490402, 2490409, 2490416, 2490420, 2490422, 2490426, 2490430, 2490431, 2490437, 2490439, 2490441, 2490442, 2490447, 2490449, 2490456, 2490464, 2490466, 2490478, 2490479, 2490486, 2490488, 2490489, 2490490, 2490497, 2490498 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-05-22 04:02:01 UTC
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:29455 https://access.redhat.com/errata/RHSA-2026:29455 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:35833 https://access.redhat.com/errata/RHSA-2026:35833 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:36199 https://access.redhat.com/errata/RHSA-2026:36199 This issue has been addressed in the following products: RHEM 1.0 for RHEL 9 Via RHSA-2026:36796 https://access.redhat.com/errata/RHSA-2026:36796 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:37072 https://access.redhat.com/errata/RHSA-2026:37072 This issue has been addressed in the following products: RHEM 1.1 for RHEL 10 RHEM 1.1 for RHEL 9 Via RHSA-2026:41019 https://access.redhat.com/errata/RHSA-2026:41019 |