Back

HIGH

golang: crypto/ssh: crafted authentication request can lead to nil pointer dereference

Published Dec 17, 2020

Description

A nil pointer dereference in the golang.org/x/crypto/ssh component through v0.0.0-20201203163018-be400aefbc4c for Go allows remote attackers to cause a denial of service against SSH servers.

Affected products

Remediation

Red Hat statement

A large number of products include the affected package, but do not make use of the vulnerable SSH server code. Accordingly, the flaw itself is rated as "Important", but these products themselves all have a "Low" severity rating. Additionally, a number of products include golang.org/x/crypto (or even golang.org/x/crypto/ssh/terminal) but not specifically golang.org/x/crypto/ssh/server.go in the final build. As this would result in a very large number of entries of not affected products, only products which include the ssh server code (golang.org/x/crypto/ssh/server.go) have been represented here. Red Hat Enterprise Linux 8 container-tools:rhel8/containernetworking-plugins is not affected because although it uses some functionality from golang.org/x/crypto, it does not use or import anything from golang.org/x/crypto/ssh/*.

Metrics

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 17, 2020
Updated Aug 4, 2024
Reserved Dec 9, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Dec 16, 2020
GHSA-3VM4-22FP-5RFM