Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
Metrics
Affected Vendors & Products
References
History
Thu, 03 Sep 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-667 |
Thu, 03 Sep 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Golang
Golang crypto |
|
| Vendors & Products |
Golang
Golang crypto |
Thu, 03 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-770 | |
| Metrics |
cvssV3_1
|
Thu, 03 Sep 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-667 |
Wed, 02 Sep 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking. | |
| Title | Prevent DoS on deadlocked established channel in golang.org/x/crypto/ssh | |
| References |
|
Status: PUBLISHED
Assigner: Go
Published: 2026-09-02T19:37:05.807Z
Updated: 2026-09-03T14:14:40.169Z
Reserved: 2026-06-23T15:10:49.353Z
Link: CVE-2026-56855
Updated: 2026-09-03T14:14:13.081Z
Status : Awaiting Analysis
Published: 2026-09-02T20:17:36.397
Modified: 2026-09-03T16:37:52.170
Link: CVE-2026-56855
No data.