GHSA-gwc9-m7rh-j2ww

    Dashboard / Vulnerabilities / GHSA-gwc9-m7rh-j2ww

    GHSA-gwc9-m7rh-j2ww

    Published: 7 Sept 2022Last Modified: 10 Sept 2026

    Summary: x/crypto/ssh vulnerable to panic via malformed packets

    Details: The x/crypto/ssh package before 0.0.0-20211202192323-5770296d904e of golang.org/x/crypto allows an unauthenticated attacker to panic an SSH server. When using AES-GCM or ChaCha20Poly1305, consuming a malformed packet which contains an empty plaintext causes a panic.

    Affected packages

    Package

    Name: golang.org/x/crypto

    Purl: pkg:golang/golang.org/x/crypto

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -0.0.0-20211202192323-5770296d904e

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-gwc9-m7rh-j2ww | CVE-DB