CVE-2026-56855
published 2026-09-02CVE-2026-56855: Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all…
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.38%
31.5th percentile
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Affected
216 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| advanced-cluster-security | rhacs-main-rhel8 | — | — |
| advanced-cluster-security | rhacs-main-rhel9 | — | — |
| advanced-cluster-security | rhacs-operator-bundle | — | — |
| advanced-cluster-security | rhacs-rhel8-operator | — | — |
| advanced-cluster-security | rhacs-rhel9-operator | — | — |
| advanced-cluster-security | rhacs-roxctl-rhel8 | — | — |
| advanced-cluster-security | rhacs-roxctl-rhel9 | — | — |
| advanced-cluster-security | rhacs-scanner-rhel8 | — | — |
| advanced-cluster-security | rhacs-scanner-rhel9 | — | — |
| advanced-cluster-security | rhacs-scanner-slim-rhel8 | — | — |
| advanced-cluster-security | rhacs-scanner-slim-rhel9 | — | — |
| advanced-cluster-security | rhacs-scanner-v4-rhel8 | — | — |
| advanced-cluster-security | rhacs-scanner-v4-rhel9 | — | — |
| assisted | agent-preinstall-image-builder-rhel9 | — | — |
| buildah_project | buildah | — | — |
| cert-manager | jetstack-cert-manager-acmesolver-rhel9 | — | — |
| cert-manager | jetstack-cert-manager-rhel9 | — | — |
| compliance | openshift-security-profiles-operator-bundle | — | — |
| compliance | openshift-security-profiles-rhel8-operator | — | — |
| container-native-virtualization | cluster-network-addons-operator | — | — |
| container-native-virtualization | cluster-network-addons-operator-rhel9 | — | — |
| container-tools_rhel8 | buildah | — | — |
| container-tools_rhel8 | podman | — | — |
| cryostat | cryostat-storage-rhel9 | — | — |
| devspaces | traefik-rhel9 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted messages
vendor_redhat·2026-09-02·CVSS 7.5
CVE-2026-56855 [HIGH] CWE-833 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted messages
golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted messages
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
A flaw was found in golang.org/x/crypto/ssh. After a channel has been established, a remote malicious peer could send specially crafted messages. This could lead to a deadlock of the entire connection, resulting in a Denial of Service (DoS) for the affected system.
Statement: A malicious SSH peer can send crafted channel messages after a connection is established, ca
VulDB
Go x-crypto-ssh up to 0.55.x allocation of resources
vuldb·2026-09-02
CVE-2026-56855 [LOW] Go x-crypto-ssh up to 0.55.x allocation of resources
A vulnerability was found in Go x-crypto-ssh up to 0.55.x and classified as problematic. This affects an unknown part. Executing a manipulation can lead to allocation of resources.
This vulnerability is registered as CVE-2026-56855. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-56855 headscale: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 headscale: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 headscale: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 golang-github-cloudflare-redoctober: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 golang-github-cloudflare-redoctober: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 golang-github-cloudflare-redoctober: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 age: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 age: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 age: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 podman-tui: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 podman-tui: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
CVE-2026-56855 podman-tui: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 docker-compose: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 docker-compose: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 docker-compose: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 gvisor-tap-vsock: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 gvisor-tap-vsock: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 gvisor-tap-vsock: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 golang-github-cloudflare-cfssl: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 golang-github-cloudflare-cfssl: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 golang-github-cloudflare-cfssl: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 gopass: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 gopass: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 gopass: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 google-osconfig-agent: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 google-osconfig-agent: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 google-osconfig-agent: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 lego: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 lego: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 lego: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 golang-x-crypto: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 golang-x-crypto: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 golang-x-crypto: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 golang-x-crypto: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 golang-x-crypto: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
CVE-2026-56855 golang-x-crypto: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 jfrog-cli: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 jfrog-cli: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 jfrog-cli: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 rclone: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 rclone: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
CVE-2026-56855 rclone: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 cri-o: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 cri-o: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 cri-o: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 kubernetes1.34: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 kubernetes1.34: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 kubernetes1.34: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 singularity-ce: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 singularity-ce: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 singularity-ce: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 trivy: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 trivy: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
CVE-2026-56855 trivy: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 vhs: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 vhs: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 vhs: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 cri-o1.30: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 cri-o1.30: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 cri-o1.30: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 hcloud: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 hcloud: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 hcloud: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 incus: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 incus: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 incus: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 apptainer: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 apptainer: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 apptainer: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 rootlesskit: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 rootlesskit: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 rootlesskit: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 transifex-client: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 transifex-client: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 transifex-client: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 DankMaterialShell: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 DankMaterialShell: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 DankMaterialShell: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 nuclei: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 nuclei: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
CVE-2026-56855 nuclei: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 trivy: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 trivy: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 trivy: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 nng: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 nng: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 nng: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Discussion:
KiCad does not use GO.
Bugzilla
CVE-2026-56855 gh: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 gh: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
CVE-2026-56855 gh: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 apptainer: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 apptainer: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
CVE-2026-56855 apptainer: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 kubernetes1.30: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 kubernetes1.30: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 kubernetes1.30: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 vagrant: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 vagrant: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 vagrant: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Discussion:
Vagrant does not ship any Golang bits => CLOSED NOTABUG
Bugzilla
CVE-2026-56855 chezmoi: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 chezmoi: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
CVE-2026-56855 chezmoi: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 golang-github-francoispqt-gojay: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 golang-github-francoispqt-gojay: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 golang-github-francoispqt-gojay: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 cri-o1.34: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 cri-o1.34: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 cri-o1.34: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 google-guest-agent: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 google-guest-agent: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 google-guest-agent: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 singularity-ce: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 singularity-ce: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
CVE-2026-56855 singularity-ce: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 opentofu: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 opentofu: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 opentofu: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 cri-o1.36: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 cri-o1.36: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 cri-o1.36: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 cri-o1.35: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 cri-o1.35: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 cri-o1.35: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 forgejo: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 forgejo: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 forgejo: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 forgejo-runner: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 forgejo-runner: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 forgejo-runner: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 golang-github-acme-lego: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 golang-github-acme-lego: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 golang-github-acme-lego: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 gopass-jsonapi: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 gopass-jsonapi: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 gopass-jsonapi: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 doctl: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 doctl: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 doctl: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 jfrog-cli: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 jfrog-cli: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
CVE-2026-56855 jfrog-cli: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 golang-github-git-5: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 golang-github-git-5: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 golang-github-git-5: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 openbao: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 openbao: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
CVE-2026-56855 openbao: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 restic: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 restic: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 restic: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 podman-tui: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 podman-tui: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 podman-tui: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 restic: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 restic: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
CVE-2026-56855 restic: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 matterbridge: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 matterbridge: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
CVE-2026-56855 matterbridge: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 forgejo-runner: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 forgejo-runner: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
CVE-2026-56855 forgejo-runner: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 containers-common: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 containers-common: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 containers-common: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 openbao: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 openbao: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 openbao: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 moby-engine: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 moby-engine: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 moby-engine: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 nuclei: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 nuclei: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 nuclei: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 mockery: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 mockery: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 mockery: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Discussion:
Not reported by govulncheck
Bugzilla
CVE-2026-56855 caddy: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 caddy: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 caddy: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 kubernetes1.32: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 kubernetes1.32: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 kubernetes1.32: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 caddy: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 caddy: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
CVE-2026-56855 caddy: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 k9s: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 k9s: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 k9s: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 gopass-hibp: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 gopass-hibp: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 gopass-hibp: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 kubernetes1.33: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 kubernetes1.33: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 kubernetes1.33: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 docker-buildkit: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 docker-buildkit: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 docker-buildkit: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 golang-github-facebookincubator-go2chef: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 golang-github-facebookincubator-go2chef: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 golang-github-facebookincubator-go2chef: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 pack: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 pack: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
CVE-2026-56855 pack: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 kubernetes1.35: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 kubernetes1.35: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 kubernetes1.35: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 age: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 age: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
CVE-2026-56855 age: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 rclone: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 rclone: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 rclone: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 chezmoi: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 chezmoi: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 chezmoi: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 buildah: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 buildah: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 buildah: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 tailscale: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 tailscale: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 tailscale: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 cri-o1.33: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 cri-o1.33: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 cri-o1.33: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 complyctl: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 complyctl: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 complyctl: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 nebula: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 nebula: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 nebula: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 opkssh: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 opkssh: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 opkssh: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 prometheus-podman-exporter: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 prometheus-podman-exporter: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 prometheus-podman-exporter: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 inspektor-gadget: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 inspektor-gadget: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 inspektor-gadget: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 kubernetes1.31: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 kubernetes1.31: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 kubernetes1.31: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 cheat: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 cheat: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 cheat: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 prometheus-podman-exporter: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 prometheus-podman-exporter: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
CVE-2026-56855 prometheus-podman-exporter: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 golang-github-theoapp-theo-agent: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 golang-github-theoapp-theo-agent: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 golang-github-theoapp-theo-agent: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 grype: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 grype: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 grype: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 kubernetes1.36: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 kubernetes1.36: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 kubernetes1.36: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 gh: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 gh: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 gh: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 cri-o1.32: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 cri-o1.32: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 cri-o1.32: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 opkssh: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 opkssh: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
CVE-2026-56855 opkssh: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 docker-buildx: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 docker-buildx: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 docker-buildx: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 matterbridge: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 matterbridge: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 matterbridge: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 pack: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 pack: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 pack: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 trayscale: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 trayscale: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 trayscale: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 cri-o1.31: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 cri-o1.31: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 cri-o1.31: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 forgejo: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 forgejo: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
CVE-2026-56855 forgejo: golang.org/x/crypto/ssh: Denial of Service via crafted messages [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 podman: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 podman: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 podman: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 ollama: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 ollama: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
CVE-2026-56855 ollama: golang.org/x/crypto/ssh: Denial of Service via crafted messages [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Bugzilla
CVE-2026-56855 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted messages
bugzilla·2026-09-03·CVSS 7.5
CVE-2026-56855 [HIGH] CVE-2026-56855 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted messages
CVE-2026-56855 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted messages
Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
2026-09-02
Published