VDB
Sign up
HIGH7.5

GHSA-gwc9-m7rh-j2ww

x/crypto/ssh vulnerable to panic via malformed packets

Quick fix

GHSA-gwc9-m7rh-j2ww — golang.org/x/crypto: upgrade to the fixed version with the command below.

go get golang.org/x/crypto@v0.0.0-20211202192323-5770296d904e

Details

The x/crypto/ssh package before 0.0.0-20211202192323-5770296d904e of golang.org/x/crypto allows an unauthenticated attacker to panic an SSH server. When using AES-GCM or ChaCha20Poly1305, consuming a malformed packet which contains an empty plaintext causes a panic.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/golang.org/x/crypto
Introduced in: 0Fixed in: 0.0.0-20211202192323-5770296d904e
Fixgo get golang.org/x/crypto@v0.0.0-20211202192323-5770296d904e

References