GO-2026-5020
Dashboard / Vulnerabilities / GO-2026-5020
Summary: Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh
Details: When writing data larger than 4GB in a single Write call on an SSH channel, an integer overflow in the internal payload size calculation caused the write loop to spin indefinitely, sending empty packets without making progress. The size comparison now uses int64 to prevent truncation.
References: https://go.dev/issue/79567, https://groups.google.com/g/golang-announce/c/a082jnz-LvI, https://go.dev/cl/781663
Affected packages
Package
Name: golang.org/x/crypto
Purl: pkg:golang/golang.org/x/crypto
Affected ranges
Type: SEMVER
Events:
Introduced- 0
Fixed -0.52.0
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
