VDB
Sign up
MEDIUM5.3

GHSA-j5w8-q4qc-rx2x

golang.org/x/crypto/ssh allows an attacker to cause unbounded memory consumption

Quick fix

GHSA-j5w8-q4qc-rx2x — golang.org/x/crypto: upgrade to the fixed version with the command below.

go get golang.org/x/crypto@v0.45.0

Details

SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/golang.org/x/crypto
Introduced in: 0Fixed in: 0.45.0
Fixgo get golang.org/x/crypto@v0.45.0

References