cbcvebase.
CVE-2022-27191
published 2022-03-18

CVE-2022-27191: The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey.

Affected

8 ranges
VendorProductVersion rangeFixed in
debiangolang-go.crypto< golang-go.crypto 1:0.0~git20220315.3147a52-1 (bookworm)golang-go.crypto 1:0.0~git20220315.3147a52-1 (bookworm)
fedoraprojectextra_packages_for_enterprise_linux
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
golang.orgx_crypto>= 0 < 0.0.0-20220314234659-1baeb1ce4c0b0.0.0-20220314234659-1baeb1ce4c0b
golangssh< 0.0.0-20220314234659-1baeb1ce4c0b0.0.0-20220314234659-1baeb1ce4c0b
redhatadvanced_cluster_management_for_kubernetes

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH