VDB
Sign up
MEDIUM5.3

GHSA-f6x5-jh6r-wrfv

golang.org/x/crypto/ssh/agent vulnerable to panic if message is malformed due to out of bounds read

Quick fix

GHSA-f6x5-jh6r-wrfv — golang.org/x/crypto: upgrade to the fixed version with the command below.

go get golang.org/x/crypto@v0.45.0

Details

SSH Agent servers do not validate the size of messages when processing new identity requests, which may cause the program to panic if the message is malformed due to an out of bounds read.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/golang.org/x/crypto
Introduced in: 0Fixed in: 0.45.0
Fixgo get golang.org/x/crypto@v0.45.0

References