Fedora Account System
Red Hat Associate
Red Hat Customer
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process. The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256, sk-ssh-ed25519) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
confirmed { "vulnerability": { "@id": "https://pkg.go.dev/vuln/GO-2026-5019", "name": "GO-2026-5019", "description": "Invoking bypass of FIDO/U2F security keys physical interaction in gola ng.org/x/crypto/ssh", "aliases": [ "CVE-2026-39831" ] }, "products": [ { "@id": "Unknown Product", "subcomponents": [ { "@id": "pkg:golang/golang.org%2Fx%2Fcrypto.0" } ] } ], "status": "affected" },
This bug appears to have been reported against 'rawhide' during the Fedora Linux 45 development cycle. Changing version to 45.