cbcvebase.
CVE-2022-27191
published 2022-03-18

CVE-2022-27191: The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving…

PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.93%
89.2th percentile
The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey.

Affected

8 ranges
VendorProductVersion rangeFixed in
debiangolang-go.crypto< golang-go.crypto 1:0.0~git20220315.3147a52-1 (bookworm)golang-go.crypto 1:0.0~git20220315.3147a52-1 (bookworm)
fedoraprojectextra_packages_for_enterprise_linux
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
golang.orgx_crypto>= 0 < 0.0.0-20220314234659-1baeb1ce4c0b0.0.0-20220314234659-1baeb1ce4c0b
golangssh< 0.0.0-20220314234659-1baeb1ce4c0b0.0.0-20220314234659-1baeb1ce4c0b
redhatadvanced_cluster_management_for_kubernetes

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.