vulnerability
Red Hat OpenShift: CVE-2022-27191: golang: crash in a golang.org/x/crypto/ssh server
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
4 | (AV:N/AC:M/Au:N/C:N/I:N/A:P) | 2022-03-18 | 2022-08-11 | 2025-04-11 |
Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
Published
2022-03-18
Added
2022-08-11
Modified
2025-04-11
Description
The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey.
Solution(s)
linuxrpm-upgrade-cri-olinuxrpm-upgrade-openshift-clientslinuxrpm-upgrade-openshift4-wincw-windows-machine-config-rhel8-operator
References
- CVE-2022-27191
- https://attackerkb.com/topics/CVE-2022-27191
- REDHAT-RHSA-2022:1476
- REDHAT-RHSA-2022:4956
- REDHAT-RHSA-2022:5068
- REDHAT-RHSA-2022:5069
- REDHAT-RHSA-2022:6347
- REDHAT-RHSA-2022:6526
- REDHAT-RHSA-2022:6527
- REDHAT-RHSA-2022:7401
- REDHAT-RHSA-2022:7457
- REDHAT-RHSA-2022:7469
- REDHAT-RHSA-2022:7954
- REDHAT-RHSA-2022:8008
- REDHAT-RHSA-2022:8634
- REDHAT-RHSA-2022:8893
- REDHAT-RHSA-2022:8932
- REDHAT-RHSA-2022:8938
- REDHAT-RHSA-2022:9096
- REDHAT-RHSA-2022:9107
- REDHAT-RHSA-2023:1325
- REDHAT-RHSA-2023:1326
- REDHAT-RHSA-2023:3366
- REDHAT-RHSA-2023:3943
- REDHAT-RHSA-2023:4488

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.