CVE-2026-78662
published 2026-09-02CVE-2026-78662: Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.32%
24.5th percentile
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Affected
216 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| advanced-cluster-security | rhacs-main-rhel8 | — | — |
| advanced-cluster-security | rhacs-main-rhel9 | — | — |
| advanced-cluster-security | rhacs-operator-bundle | — | — |
| advanced-cluster-security | rhacs-rhel8-operator | — | — |
| advanced-cluster-security | rhacs-rhel9-operator | — | — |
| advanced-cluster-security | rhacs-roxctl-rhel8 | — | — |
| advanced-cluster-security | rhacs-roxctl-rhel9 | — | — |
| advanced-cluster-security | rhacs-scanner-rhel8 | — | — |
| advanced-cluster-security | rhacs-scanner-rhel9 | — | — |
| advanced-cluster-security | rhacs-scanner-slim-rhel8 | — | — |
| advanced-cluster-security | rhacs-scanner-slim-rhel9 | — | — |
| advanced-cluster-security | rhacs-scanner-v4-rhel8 | — | — |
| advanced-cluster-security | rhacs-scanner-v4-rhel9 | — | — |
| assisted | agent-preinstall-image-builder-rhel9 | — | — |
| buildah_project | buildah | — | — |
| cert-manager | jetstack-cert-manager-acmesolver-rhel9 | — | — |
| cert-manager | jetstack-cert-manager-rhel9 | — | — |
| compliance | openshift-security-profiles-operator-bundle | — | — |
| compliance | openshift-security-profiles-rhel8-operator | — | — |
| container-native-virtualization | cluster-network-addons-operator | — | — |
| container-native-virtualization | cluster-network-addons-operator-rhel9 | — | — |
| container-tools_rhel8 | buildah | — | — |
| container-tools_rhel8 | podman | — | — |
| cryostat | cryostat-storage-rhel9 | — | — |
| devspaces | traefik-rhel9 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Go x-crypto-ssh up to 0.55.x Channel handlePacket allocation of resources
vuldb·2026-09-02
CVE-2026-78662 [LOW] Go x-crypto-ssh up to 0.55.x Channel handlePacket allocation of resources
A vulnerability was found in Go x-crypto-ssh up to 0.55.x. It has been classified as problematic. This vulnerability affects the function handlePacket of the component Channel. The manipulation leads to allocation of resources.
This vulnerability is documented as CVE-2026-78662. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.
Red Hat
golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via channel request flooding
vendor_redhat·2026-09-02·CVSS 7.5
CVE-2026-78662 [HIGH] CWE-833 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via channel request flooding
golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via channel request flooding
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
A flaw was found in golang.org/x/crypto/ssh. A malicious remote attacker could flood a channel's incoming requests before it is established, leading to a deadlock of the entire connection. This could result in a denial of service (DoS) for legitimate users.
Statement: A malicious
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-78662 vagrant: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 vagrant: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 vagrant: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Discussion:
Vagrant does not ship any Golan
Bugzilla
CVE-2026-78662 opentofu: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 opentofu: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 opentofu: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 golang-github-cloudflare-redoctober: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 golang-github-cloudflare-redoctober: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 golang-github-cloudflare-redoctober: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 trayscale: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 trayscale: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 trayscale: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 docker-buildkit: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 docker-buildkit: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 docker-buildkit: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 gopass-jsonapi: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 gopass-jsonapi: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 gopass-jsonapi: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 ollama: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 ollama: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 ollama: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 containers-common: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 containers-common: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 containers-common: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 chezmoi: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 chezmoi: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 chezmoi: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 golang-github-acme-lego: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 golang-github-acme-lego: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 golang-github-acme-lego: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 buildah: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 buildah: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 buildah: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 openbao: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 openbao: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 openbao: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 cri-o1.30: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 cri-o1.30: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 cri-o1.30: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 transifex-client: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 transifex-client: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 transifex-client: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 golang-x-crypto: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 golang-x-crypto: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 golang-x-crypto: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 cri-o1.32: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 cri-o1.32: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 cri-o1.32: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 age: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 age: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 age: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 kubernetes1.36: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 kubernetes1.36: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 kubernetes1.36: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 forgejo: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 forgejo: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
CVE-2026-78662 forgejo: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 openbao: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 openbao: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
CVE-2026-78662 openbao: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 podman: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 podman: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 podman: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Discussion:
The clickable CVE link in bz tit
Bugzilla
CVE-2026-78662 docker-compose: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 docker-compose: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 docker-compose: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 jfrog-cli: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 jfrog-cli: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
CVE-2026-78662 jfrog-cli: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 headscale: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 headscale: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 headscale: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 gopass: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 gopass: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 gopass: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 cri-o1.35: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 cri-o1.35: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 cri-o1.35: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 chezmoi: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 chezmoi: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
CVE-2026-78662 chezmoi: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 podman-tui: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 podman-tui: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 podman-tui: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 cri-o: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 cri-o: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 cri-o: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 nebula: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 nebula: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 nebula: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 nuclei: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 nuclei: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 nuclei: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 moby-engine: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 moby-engine: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 moby-engine: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 inspektor-gadget: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 inspektor-gadget: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 inspektor-gadget: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 google-guest-agent: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 google-guest-agent: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 google-guest-agent: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 gh: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 gh: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 gh: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 singularity-ce: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 singularity-ce: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
CVE-2026-78662 singularity-ce: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 kubernetes1.32: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 kubernetes1.32: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 kubernetes1.32: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 kubernetes1.35: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 kubernetes1.35: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 kubernetes1.35: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 trivy: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 trivy: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 trivy: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 cri-o1.33: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 cri-o1.33: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 cri-o1.33: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 caddy: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 caddy: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 caddy: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 forgejo-runner: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 forgejo-runner: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 forgejo-runner: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 matterbridge: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 matterbridge: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 matterbridge: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 rclone: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 rclone: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 rclone: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 jfrog-cli: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 jfrog-cli: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 jfrog-cli: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 apptainer: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 apptainer: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
CVE-2026-78662 apptainer: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 cri-o1.36: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 cri-o1.36: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 cri-o1.36: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 pack: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 pack: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 pack: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 caddy: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 caddy: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
CVE-2026-78662 caddy: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 rootlesskit: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 rootlesskit: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 rootlesskit: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 cri-o1.34: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 cri-o1.34: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 cri-o1.34: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 kubernetes1.34: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 kubernetes1.34: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 kubernetes1.34: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 forgejo: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 forgejo: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 forgejo: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 golang-github-git-5: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 golang-github-git-5: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 golang-github-git-5: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 podman-tui: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 podman-tui: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
CVE-2026-78662 podman-tui: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 opkssh: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 opkssh: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 opkssh: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 singularity-ce: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 singularity-ce: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 singularity-ce: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 lego: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 lego: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 lego: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 opkssh: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 opkssh: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
CVE-2026-78662 opkssh: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 kubernetes1.30: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 kubernetes1.30: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 kubernetes1.30: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 prometheus-podman-exporter: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 prometheus-podman-exporter: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 prometheus-podman-exporter: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 rclone: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 rclone: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
CVE-2026-78662 rclone: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 restic: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 restic: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
CVE-2026-78662 restic: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 gopass-hibp: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 gopass-hibp: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 gopass-hibp: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 golang-github-francoispqt-gojay: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 golang-github-francoispqt-gojay: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 golang-github-francoispqt-gojay: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 incus: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 incus: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 incus: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 nng: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 nng: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 nng: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Discussion:
KiCad does not use GO.
Bugzilla
CVE-2026-78662 vhs: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 vhs: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 vhs: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 golang-github-cloudflare-cfssl: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 golang-github-cloudflare-cfssl: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 golang-github-cloudflare-cfssl: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 restic: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 restic: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 restic: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 doctl: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 doctl: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 doctl: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 trivy: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 trivy: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
CVE-2026-78662 trivy: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 forgejo-runner: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 forgejo-runner: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
CVE-2026-78662 forgejo-runner: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 hcloud: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 hcloud: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 hcloud: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 google-osconfig-agent: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 google-osconfig-agent: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 google-osconfig-agent: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 DankMaterialShell: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 DankMaterialShell: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 DankMaterialShell: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 complyctl: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 complyctl: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 complyctl: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 gvisor-tap-vsock: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 gvisor-tap-vsock: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 gvisor-tap-vsock: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 cheat: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 cheat: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 cheat: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 gh: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 gh: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
CVE-2026-78662 gh: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 golang-github-facebookincubator-go2chef: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 golang-github-facebookincubator-go2chef: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 golang-github-facebookincubator-go2chef: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 k9s: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 k9s: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 k9s: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 matterbridge: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 matterbridge: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
CVE-2026-78662 matterbridge: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 pack: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 pack: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
CVE-2026-78662 pack: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 kubernetes1.31: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 kubernetes1.31: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 kubernetes1.31: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 prometheus-podman-exporter: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 prometheus-podman-exporter: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
CVE-2026-78662 prometheus-podman-exporter: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 nuclei: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 nuclei: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
CVE-2026-78662 nuclei: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 golang-x-crypto: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 golang-x-crypto: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
CVE-2026-78662 golang-x-crypto: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 docker-buildx: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 docker-buildx: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 docker-buildx: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 kubernetes1.33: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 kubernetes1.33: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 kubernetes1.33: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 golang-github-theoapp-theo-agent: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 golang-github-theoapp-theo-agent: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 golang-github-theoapp-theo-agent: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 tailscale: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 tailscale: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 tailscale: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 apptainer: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 apptainer: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 apptainer: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 age: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 age: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
CVE-2026-78662 age: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 grype: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 grype: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 grype: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 cri-o1.31: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
bugzilla·2026-09-09·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 cri-o1.31: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
CVE-2026-78662 cri-o1.31: golang.org/x/crypto/ssh: Denial of Service via channel request flooding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Bugzilla
CVE-2026-78662 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via channel request flooding
bugzilla·2026-09-03·CVSS 7.5
CVE-2026-78662 [HIGH] CVE-2026-78662 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via channel request flooding
CVE-2026-78662 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via channel request flooding
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
2026-09-02
Published