Skip to content

update: golang.org/x/crypto #1669

Closed
Closed
@dongsupark

Description

@dongsupark

Name: golang.org/x/crypto
CVEs: CVE-2025-22869
CVSSs: 7.5
Action Needed: update to >= 0.35.0

Summary: SSH servers which implement file transfer protocols are vulnerable to a denial of service attack from clients which complete the key exchange slowly, or not at all, causing pending content to be read into memory, but never transmitted.

See also https://groups.google.com/g/golang-announce/c/qN_GDasRQSA.

refmap.gentoo: TBD

Metadata

Metadata

Assignees

No one assigned

    Labels

    advisorysecurity advisorycvss/HIGH> 7 && < 9 assessed CVSSsecuritysecurity concerns

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions