Fedora Account System
Red Hat Associate
Red Hat Customer
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process. The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256, sk-ssh-ed25519) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, return a "no-touch-required" extension in Permissions.Extensions from PublicKeyCallback.
cli [ 29.x] Elapsed: 2s ❯ go mod why -m golang.org/x/crypto/ssh # golang.org/x/crypto/ssh (main module does not need module golang.org/x/crypto/ssh) cli [ 29.x] ❯ cd ../moby/ moby [ docker-29.x][?] ❯ go mod why -m golang.org/x/crypto/ssh # golang.org/x/crypto/ssh (main module does not need module golang.org/x/crypto/ssh)