PT-2026-50253 · Mageia · Golang-X-Crypto+1

Publicado

2026-06-07

·

Atualizado

2026-06-07

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
fixes a protocol weakness in the golang.org/x/crypto/ssh package that allowed a MITM attacker to compromise the integrity of the secure channel before it was established, allowing them to prevent transmission of a number of messages immediately after the secure channel was established without either side being aware. The impact of this attack is relatively limited, as it does not compromise confidentiality of the channel. Notably this attack would allow an attacker to prevent the transmission of the SSH2 MSG EXT INFO message, disabling a handful of newer security features.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

MGASA-2026-0179

Produtos afetados

Golang-X-Crypto
Golang-X-Sys