vulnerability

Red Hat OpenShift: CVE-2022-27191: golang: crash in a golang.org/x/crypto/ssh server

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
Published
2022-03-18
Added
2022-08-11
Modified
2025-04-11

Description

The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey.

Solution(s)

linuxrpm-upgrade-cri-olinuxrpm-upgrade-openshift-clientslinuxrpm-upgrade-openshift4-wincw-windows-machine-config-rhel8-operator
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.