Bug 2480678 (CVE-2026-46597) - CVE-2026-46597 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs
Summary: CVE-2026-46597 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Se...
Keywords:
Status: NEW
Alias: CVE-2026-46597
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2509294 2509296 2509299 2509300 2509303 2509305 2509307 2509308 2509309 2509310 2509313 2509316 2509317 2509318 2509319 2509320 2509321 2509322 2509323 2509324 2509325 2509326 2509327 2509328 2509329 2509330 2509332 2509333 2509334 2509336 2509337 2509338 2509339 2509341 2509342 2509346 2509349 2509350 2509351 2509354 2509355 2509357 2509358 2509359 2509360 2509361 2509362 2509363 2509365 2509367 2509368 2509369 2509370 2509372 2509373 2509378 2509379 2509380 2509381 2509383 2509385 2509386 2509387 2509388 2509295 2509297 2509298 2509301 2509302 2509304 2509306 2509311 2509312 2509314 2509315 2509331 2509335 2509340 2509344 2509345 2509347 2509348 2509352 2509353 2509356 2509364 2509366 2509371 2509374 2509375 2509376 2509377 2509382 2509384
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-05-22 04:01 UTC by OSIDB Bzimport
Modified: 2026-08-26 05:57 UTC (History)
111 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:51036 0 None None None 2026-08-11 10:14:12 UTC

Description OSIDB Bzimport 2026-05-22 04:01:44 UTC
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.

Comment 7 errata-xmlrpc 2026-08-11 10:14:08 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.22

Via RHSA-2026:51036 https://access.redhat.com/errata/RHSA-2026:51036


Note You need to log in before you can comment on or make changes to this bug.