Back

HIGH

golang.org/x/crypto: Processing of crafted ssh-ed25519 public keys allows for panic

Published Feb 20, 2020

Description

golang.org/x/crypto before v0.0.0-20200220183623-bac4c82f6975 for Go allows a panic during signature verification in the golang.org/x/crypto/ssh package. A client can attack an SSH server that accepts public keys. Also, a server can attack any SSH client.

Affected products

Remediation

Red Hat statement

OpenShift Container Platform uses the vulnerable library in a number of components but strictly as an SSH client. The severity of this vulnerability is reduced for clients as it requires connections to malicious SSH servers, with the maximum impact only a client crash. This vulnerability is rated Low for OpenShift Container Platform.

Metrics

Weaknesses (2)

References (18)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 20, 2020
Updated Aug 4, 2024
Reserved Feb 19, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Feb 21, 2020
GHSA-FFHG-7MH4-33C4