Bug 2480681 (CVE-2026-39829) - CVE-2026-39829 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters
Summary: CVE-2026-39829 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Se...
Keywords:
Status: NEW
Alias: CVE-2026-39829
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2490030 2490032 2490034 2490035 2490036 2490037 2490038 2490041 2490042 2490043 2490045 2490047 2490051 2490052 2490053 2490054 2490055 2490057 2490058 2490059 2490060 2490065 2490066 2490068 2490070 2490073 2490074 2490075 2490076 2490077 2490079 2490080 2490081 2490082 2490084 2490085 2490087 2490088 2490089 2490090 2490092 2490093 2490094 2490095 2490096 2490097 2490098 2490101 2490104 2490105 2490106 2490107 2490108 2490109 2490110 2490111 2490112 2490113 2490114 2490115 2490116 2490120 2490121 2490122 2490123 2490124 2490029 2490031 2490033 2490039 2490040 2490044 2490046 2490048 2490049 2490050 2490056 2490061 2490062 2490063 2490064 2490067 2490069 2490071 2490072 2490078 2490083 2490086 2490091 2490099 2490100 2490102 2490103 2490117
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-05-22 04:01 UTC by OSIDB Bzimport
Modified: 2026-07-16 14:32 UTC (History)
77 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:29455 0 None None None 2026-06-24 23:49:36 UTC
Red Hat Product Errata RHSA-2026:35833 0 None None None 2026-07-06 04:52:35 UTC
Red Hat Product Errata RHSA-2026:36199 0 None None None 2026-07-07 13:00:11 UTC
Red Hat Product Errata RHSA-2026:36796 0 None None None 2026-07-08 15:51:04 UTC
Red Hat Product Errata RHSA-2026:37072 0 None None None 2026-07-09 05:14:29 UTC
Red Hat Product Errata RHSA-2026:37123 0 None None None 2026-07-09 07:15:44 UTC
Red Hat Product Errata RHSA-2026:41019 0 None None None 2026-07-16 14:32:16 UTC

Description OSIDB Bzimport 2026-05-22 04:01:52 UTC
The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus or DSA parameter could cause several minutes of CPU consumption during signature verification. This could be triggered by unauthenticated clients during public key authentication. RSA moduli are now limited to 8192 bits, and DSA parameters are validated per FIPS 186-2.

Comment 2 errata-xmlrpc 2026-06-24 23:49:31 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:29455 https://access.redhat.com/errata/RHSA-2026:29455

Comment 5 errata-xmlrpc 2026-07-06 04:52:31 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:35833 https://access.redhat.com/errata/RHSA-2026:35833

Comment 6 errata-xmlrpc 2026-07-07 13:00:06 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:36199 https://access.redhat.com/errata/RHSA-2026:36199

Comment 7 errata-xmlrpc 2026-07-08 15:50:59 UTC
This issue has been addressed in the following products:

  RHEM 1.0 for RHEL 9

Via RHSA-2026:36796 https://access.redhat.com/errata/RHSA-2026:36796

Comment 8 errata-xmlrpc 2026-07-09 05:14:25 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:37072 https://access.redhat.com/errata/RHSA-2026:37072

Comment 9 errata-xmlrpc 2026-07-09 07:15:39 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:37123 https://access.redhat.com/errata/RHSA-2026:37123

Comment 10 errata-xmlrpc 2026-07-16 14:32:11 UTC
This issue has been addressed in the following products:

  RHEM 1.1 for RHEL 10
  RHEM 1.1 for RHEL 9

Via RHSA-2026:41019 https://access.redhat.com/errata/RHSA-2026:41019


Note You need to log in before you can comment on or make changes to this bug.