golang: crypto/ssh: crafted authentication request can lead to nil pointer dereference
Published Dec 17, 2020
7.5
HIGHCVSS 3.1
EPSS 3.27%
Description
A nil pointer dereference in the golang.org/x/crypto/ssh component through v0.0.0-20201203163018-be400aefbc4c for Go allows remote attackers to cause a denial of service against SSH servers.
Affected products
No data.
No data.
RHEL-8-CNV-4.8
container-native-virtualization/vm-import-operator-rhel8:v4.8.0-18
Fixed · RHSA-2021:2920
Red Hat Enterprise Linux 8
container-tools:rhel8-8040020210407081426.59631bd5
Fixed · RHSA-2021:1796
Red Hat OpenShift Container Platform 4.7
openshift4/ose-aws-ebs-csi-driver-rhel8:v4.7.0-202102130115.p0
Fixed · RHSA-2020:5633
Red Hat OpenShift Container Platform 4.7
openshift4/ose-azure-machine-controllers:v4.7.0-202102130115.p0
Fixed · RHSA-2020:5633
Red Hat OpenShift Container Platform 4.7
openshift4/ose-baremetal-installer-rhel8:v4.7.0-202102130115.p0
Fixed · RHSA-2020:5633
Red Hat OpenShift Container Platform 4.7
openshift4/ose-installer-artifacts:v4.7.0-202102130115.p0
Fixed · RHSA-2020:5633
Red Hat OpenShift Container Platform 4.7
openshift4/ose-installer:v4.7.0-202102130115.p0
Fixed · RHSA-2020:5633
OpenShift Service Mesh 2.0
3scale-istio-adapter-rhel8-container
Affected
OpenShift Service Mesh 2.0
servicemesh
Affected
OpenShift Service Mesh 2.0
servicemesh-cni
Affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/multicluster-operators-subscription-release-rhel8
Affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/multicluster-operators-subscription-rhel9
Affected
Red Hat Enterprise Linux 7
gomtree
Out of support scope
Red Hat OpenShift Container Platform 3.11
atomic-openshift
Fix deferred
Red Hat OpenShift Container Platform 3.11
atomic-openshift-cluster-autoscaler
Fix deferred
Red Hat OpenShift Container Platform 3.11
atomic-openshift-descheduler
Fix deferred
Red Hat OpenShift Container Platform 3.11
atomic-openshift-dockerregistry
Fix deferred
Red Hat OpenShift Container Platform 3.11
atomic-openshift-service-idler
Fix deferred
Red Hat OpenShift Container Platform 3.11
atomic-openshift-web-console
Fix deferred
Red Hat OpenShift Container Platform 3.11
csi-attacher
Fix deferred
Red Hat OpenShift Container Platform 3.11
csi-driver-registrar
Fix deferred
Red Hat OpenShift Container Platform 3.11
csi-provisioner
Fix deferred
Red Hat OpenShift Container Platform 3.11
golang-github-openshift-oauth-proxy
Not affected
Red Hat OpenShift Container Platform 3.11
openshift-enterprise-cluster-capacity
Fix deferred
Red Hat OpenShift Container Platform 3.11
openshift-enterprise-image-registry
Fix deferred
Red Hat OpenShift Container Platform 3.11
openshift-eventrouter
Fix deferred
Red Hat OpenShift Container Platform 3.11
openshift-external-storage
Fix deferred
Red Hat OpenShift Container Platform 3.11
openvswitch-ovn-kubernetes
Fix deferred
Red Hat OpenShift Container Platform 4
cri-o
Not affected
Red Hat OpenShift Container Platform 4
csi-driver-manilla-container
Affected
Red Hat OpenShift Container Platform 4
openshift
Fix deferred
Red Hat OpenShift Container Platform 4
openshift4/ose-aws-ebs-csi-driver-rhel9
Affected
Red Hat OpenShift Container Platform 4
openshift4/ose-baremetal-installer-rhel8
Affected
Red Hat OpenShift Container Platform 4
openshift4/ose-cluster-autoscaler
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-cluster-bootstrap-rhel9
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-cluster-logging-operator
Fix deferred
Red Hat OpenShift Container Platform 4
openshift4/ose-cluster-network-operator
Fix deferred
Red Hat OpenShift Container Platform 4
openshift4/ose-csi-driver-nfs-rhel8
Affected
Red Hat OpenShift Container Platform 4
openshift4/ose-hyperkube
Fix deferred
Red Hat OpenShift Container Platform 4
openshift4/ose-installer-artifacts-rhel9
Affected
Red Hat OpenShift Container Platform 4
openshift4/ose-installer-rhel9
Affected
Red Hat OpenShift Container Platform 4
openshift4/ose-metering-helm-container-rhel8
Fix deferred
Red Hat OpenShift Container Platform 4
openshift4/ose-node-feature-discovery
Fix deferred
Red Hat OpenShift Container Platform 4
openshift4/ose-sriov-dp-admission-controller
Affected
Red Hat OpenShift Container Platform 4
openshift4/ose-tests
Fix deferred
Red Hat OpenShift Container Platform 4
openshift4/ose-vertical-pod-autoscaler-rhel8
Fix deferred
Red Hat OpenShift Container Platform 4
openshift4/ose-vertical-pod-autoscaler-rhel8-operator
Fix deferred
Red Hat OpenShift Container Platform 4
podman
Fix deferred
Red Hat OpenShift Virtualization 2
cluster-network-addons-operator-container
Fix deferred
Red Hat OpenShift Virtualization 2
hyperconverged-cluster-operator-container
Affected
Red Hat OpenShift Virtualization 2
kubernetes-nmstate-handler-container
Fix deferred
Red Hat OpenShift Virtualization 2
virt-api-container
Affected
Red Hat OpenShift Virtualization 2
virt-controller-container
Affected
Red Hat OpenShift Virtualization 2
virt-handler-container
Affected
Red Hat OpenShift Virtualization 2
virt-launcher-container
Affected
Red Hat OpenShift Virtualization 2
virt-operator-container
Affected
Red Hat Openshift Container Storage 4
ocs4/cephcsi-rhel8
Fix deferred
Red Hat Storage 3
heketi
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| RHEL-8-CNV-4.8 | container-native-virtualization/vm-import-operator-rhel8:v4.8.0-18 | Fixed | RHSA-2021:2920 |
| Red Hat Enterprise Linux 8 | container-tools:rhel8-8040020210407081426.59631bd5 | Fixed | RHSA-2021:1796 |
| Red Hat OpenShift Container Platform 4.7 | openshift4/ose-aws-ebs-csi-driver-rhel8:v4.7.0-202102130115.p0 | Fixed | RHSA-2020:5633 |
| Red Hat OpenShift Container Platform 4.7 | openshift4/ose-azure-machine-controllers:v4.7.0-202102130115.p0 | Fixed | RHSA-2020:5633 |
| Red Hat OpenShift Container Platform 4.7 | openshift4/ose-baremetal-installer-rhel8:v4.7.0-202102130115.p0 | Fixed | RHSA-2020:5633 |
| Red Hat OpenShift Container Platform 4.7 | openshift4/ose-installer-artifacts:v4.7.0-202102130115.p0 | Fixed | RHSA-2020:5633 |
| Red Hat OpenShift Container Platform 4.7 | openshift4/ose-installer:v4.7.0-202102130115.p0 | Fixed | RHSA-2020:5633 |
| OpenShift Service Mesh 2.0 | 3scale-istio-adapter-rhel8-container | Affected | n/a |
| OpenShift Service Mesh 2.0 | servicemesh | Affected | n/a |
| OpenShift Service Mesh 2.0 | servicemesh-cni | Affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/multicluster-operators-subscription-release-rhel8 | Affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/multicluster-operators-subscription-rhel9 | Affected | n/a |
| Red Hat Enterprise Linux 7 | gomtree | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-cluster-autoscaler | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-descheduler | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-dockerregistry | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-service-idler | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-web-console | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 3.11 | csi-attacher | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 3.11 | csi-driver-registrar | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 3.11 | csi-provisioner | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 3.11 | golang-github-openshift-oauth-proxy | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.11 | openshift-enterprise-cluster-capacity | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 3.11 | openshift-enterprise-image-registry | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 3.11 | openshift-eventrouter | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 3.11 | openshift-external-storage | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 3.11 | openvswitch-ovn-kubernetes | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | cri-o | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | csi-driver-manilla-container | Affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-aws-ebs-csi-driver-rhel9 | Affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-baremetal-installer-rhel8 | Affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-cluster-autoscaler | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-cluster-bootstrap-rhel9 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-cluster-logging-operator | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-cluster-network-operator | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-csi-driver-nfs-rhel8 | Affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-hyperkube | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-installer-artifacts-rhel9 | Affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-installer-rhel9 | Affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-metering-helm-container-rhel8 | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-node-feature-discovery | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-sriov-dp-admission-controller | Affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-tests | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-vertical-pod-autoscaler-rhel8 | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-vertical-pod-autoscaler-rhel8-operator | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | podman | Fix deferred | n/a |
| Red Hat OpenShift Virtualization 2 | cluster-network-addons-operator-container | Fix deferred | n/a |
| Red Hat OpenShift Virtualization 2 | hyperconverged-cluster-operator-container | Affected | n/a |
| Red Hat OpenShift Virtualization 2 | kubernetes-nmstate-handler-container | Fix deferred | n/a |
| Red Hat OpenShift Virtualization 2 | virt-api-container | Affected | n/a |
| Red Hat OpenShift Virtualization 2 | virt-controller-container | Affected | n/a |
| Red Hat OpenShift Virtualization 2 | virt-handler-container | Affected | n/a |
| Red Hat OpenShift Virtualization 2 | virt-launcher-container | Affected | n/a |
| Red Hat OpenShift Virtualization 2 | virt-operator-container | Affected | n/a |
| Red Hat Openshift Container Storage 4 | ocs4/cephcsi-rhel8 | Fix deferred | n/a |
| Red Hat Storage 3 | heketi | Fix deferred | n/a |
golang.org/x/crypto
Go
Introduced 0 Fixed 0.0.0-20201216223049-8b5274cf687f
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | golang.org/x/crypto | 0 | 0.0.0-20201216223049-8b5274cf687f |
Remediation
Red Hat statement
A large number of products include the affected package, but do not make use of the vulnerable SSH server code. Accordingly, the flaw itself is rated as "Important", but these products themselves all have a "Low" severity rating. Additionally, a number of products include golang.org/x/crypto (or even golang.org/x/crypto/ssh/terminal) but not specifically golang.org/x/crypto/ssh/server.go in the final build. As this would result in a very large number of entries of not affected products, only products which include the ssh server code (golang.org/x/crypto/ssh/server.go) have been represented here. Red Hat Enterprise Linux 8 container-tools:rhel8/containernetworking-plugins is not affected because although it uses some functionality from golang.org/x/crypto, it does not use or import anything from golang.org/x/crypto/ssh/*.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v5
Table of values (19 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 3.27% (0.03267) | 88.00th | v5 (v2026.06.15) |
| Jun 15, 2026 | 3.23% (0.03228) | 86.58th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.54% (0.00542) | 77.55th | v3 (v2023.03.01) |
| Feb 15, 2024 | 0.54% (0.00542) | 76.68th | v3 (v2023.03.01) |
| Nov 8, 2023 | 0.54% (0.00542) | 74.66th | v3 (v2023.03.01) |
| Sep 1, 2023 | 0.78% (0.00776) | 79.12th | v3 (v2023.03.01) |
| Jul 23, 2023 | 0.68% (0.00682) | 77.35th | v3 (v2023.03.01) |
| Jul 11, 2023 | 0.85% (0.00848) | 79.91th | v3 (v2023.03.01) |
| Jun 27, 2023 | 0.60% (0.00599) | 75.42th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.58% (0.00578) | 74.69th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.14% (0.01136) | 59.45th | v2 (v2022.01.01) |
| Oct 18, 2022 | 1.14% (0.01136) | 58.28th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.14% (0.01136) | 56.27th | v2 (v2022.01.01) |
| Feb 4, 2022 | 5.74% (0.05736) | 77.22th | v2 (v2022.01.01) |
| Feb 3, 2022 | 5.58% (0.05581) | 80.18th | v1 |
| Jan 6, 2022 | 5.58% (0.05581) | 79.98th | v1 |
| Oct 18, 2021 | 1.30% (0.01300) | 69.91th | v1 |
| Sep 1, 2021 | 0.98% (0.00976) | 61.78th | v1 |
| Apr 14, 2021 | 0.98% (0.00976) | 0.00th | v1 |
References (12)
- https://access.redhat.com/security/cve/CVE-2020-29652 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1908883 Issue Tracking
- https://github.com/advisories/GHSA-3vm4-22fp-5rfm Advisory
- https://go-review.googlesource.com/c/crypto/+/278852 x_refsource_MISCThird Party Advisory
- https://go.dev/cl/278852
- https://go.googlesource.com/crypto/+/8b5274cf687fd9316b4108863654cc57385531e8
- https://groups.google.com/g/golang-announce/c/ouZIlBimOsE?pli=1 x_refsource_MISCThird Party Advisory
- https://lists.apache.org/thread.html/r68032132c0399c29d6cdc7bd44918535da54060a10a12b1591328bff%40%3Cnotifications.skywalking.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r68032132c0399c29d6cdc7bd44918535da54060a10a12b1591328bff@%3Cnotifications.skywalking.apache.org%3E
- https://nvd.nist.gov/vuln/detail/CVE-2020-29652
- https://pkg.go.dev/vuln/GO-2021-0227
- https://www.cve.org/CVERecord?id=CVE-2020-29652
Change history (0)
No recorded changes yet.