Panic on malformed packets in golang.org/x/crypto/ssh
Overview
Source
ID
GO-2022-0968
Aliases
CVE-2021-43565
GHSA-gwc9-m7rh-j2ww
Affected package
Description
Unauthenticated clients can cause a panic in SSH servers.
When using AES-GCM or ChaCha20Poly1305, consuming a malformed packet which contains an empty plaintext causes a panic.
Summary
94.86k
Total packages affected
help_outline
Packages with at least one version that is affected by the advisory or has an affected dependency.
11.20k
Packages with a known fix
help_outline
Packages with versions affected by the advisory that have a greater version that is not affected.
7.08%
Total ecosystem affected
help_outline
The proportion of packages in the ecosystem that are affected by the advisory (fixed or not).
Affected Version: Introduced: 0, Fixed: 0.0.0-20211202192323-5770296d904e
Patched/Unaffected
Affected