PT-2026-50253 · Mageia · Golang-X-Crypto+1
Published
2026-06-07
·
Updated
2026-06-07
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
fixes a protocol weakness in the golang.org/x/crypto/ssh package that
allowed a MITM attacker to compromise the integrity of the secure
channel before it was established, allowing them to prevent transmission
of a number of messages immediately after the secure channel was
established without either side being aware.
The impact of this attack is relatively limited, as it does not
compromise confidentiality of the channel. Notably this attack would
allow an attacker to prevent the transmission of the SSH2 MSG EXT INFO
message, disabling a handful of newer security features.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Golang-X-Crypto
Golang-X-Sys