CVE-2022-27191

The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 25%
Affected Products (NVD)
VendorProductVersion
golangssh
𝑥
< 0.0.0-20220314234659-1baeb1ce4c0b
fedoraprojectextra_packages_for_enterprise_linux
8.0
redhatadvanced_cluster_management_for_kubernetes
2.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
golang-go.crypto
bookworm
1:0.4.0-1
fixed
bullseye
no-dsa
buster
postponed
sid
1:0.25.0-1
fixed
trixie
1:0.25.0-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
golang-go.crypto
bionic
needs-triage
focal
needs-triage
impish
ignored
jammy
needs-triage
kinetic
ignored
lunar
ignored
mantic
ignored
noble
needs-triage
trusty
dne
xenial
needs-triage
lxd
bionic
not-affected
focal
not-affected
impish
not-affected
jammy
dne
trusty
dne
xenial
not-affected
snapd
bionic
not-affected
focal
not-affected
impish
not-affected
jammy
not-affected
kinetic
not-affected
lunar
not-affected
mantic
not-affected
noble
not-affected
trusty
dne
xenial
not-affected
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
containerd
suse enterprise desktop 15 SP7
1.6.12-150000.79.1
fixed
suse enterprise sap 12
1.6.12-16.68.1
fixed
suse enterprise sap 12 SP3
1.6.12-16.68.1
fixed
suse enterprise sap 12 SP4
1.6.12-16.68.1
fixed
suse enterprise sap 12 SP5
1.6.12-16.68.1
fixed
suse enterprise sap 15 SP3
1.6.12-150000.79.1
fixed
suse enterprise sap 15 SP4
1.6.12-150000.79.1
fixed
suse enterprise sap 15 SP5
1.6.12-150000.79.1
fixed
suse enterprise sap 15 SP6
1.6.12-150000.79.1
fixed
suse enterprise sap 15 SP7
1.6.12-150000.79.1
fixed
suse enterprise server 12
1.6.12-16.68.1
fixed
suse enterprise server 12 SP3
1.6.12-16.68.1
fixed
suse enterprise server 12 SP4
1.6.12-16.68.1
fixed
suse enterprise server 12 SP5
1.6.12-16.68.1
fixed
suse enterprise server 15
1.6.12-150000.79.1
fixed
suse enterprise server 15 SP1
1.6.12-150000.79.1
fixed
suse enterprise server 15 SP2
1.6.12-150000.79.1
fixed
suse enterprise server 15 SP3
1.6.12-150000.79.1
fixed
suse enterprise server 15 SP4
1.6.12-150000.79.1
fixed
suse enterprise server 15 SP5
1.6.12-150000.79.1
fixed
suse enterprise server 15 SP6
1.6.12-150000.79.1
fixed
suse enterprise server 15 SP7
1.6.12-150000.79.1
fixed
containerd-ctr
suse enterprise sap 15 SP3
1.6.12-150000.79.1
fixed
suse enterprise sap 15 SP4
1.6.12-150000.79.1
fixed
suse enterprise sap 15 SP5
1.6.12-150000.79.1
fixed
suse enterprise sap 15 SP6
1.6.12-150000.79.1
fixed
suse enterprise sap 15 SP7
1.6.12-150000.79.1
fixed
suse enterprise server 15
1.6.12-150000.79.1
fixed
suse enterprise server 15 SP1
1.6.12-150000.79.1
fixed
suse enterprise server 15 SP2
1.6.12-150000.79.1
fixed
suse enterprise server 15 SP3
1.6.12-150000.79.1
fixed
suse enterprise server 15 SP4
1.6.12-150000.79.1
fixed
suse enterprise server 15 SP5
1.6.12-150000.79.1
fixed
suse enterprise server 15 SP6
1.6.12-150000.79.1
fixed
suse enterprise server 15 SP7
1.6.12-150000.79.1
fixed
containerd-devel
suse enterprise sap 15 SP5
1.6.12-150000.79.1
fixed
suse enterprise sap 15 SP6
1.6.12-150000.79.1
fixed
suse enterprise sap 15 SP7
1.6.12-150000.79.1
fixed
suse enterprise server 15 SP5
1.6.12-150000.79.1
fixed
suse enterprise server 15 SP6
1.6.12-150000.79.1
fixed
suse enterprise server 15 SP7
1.6.12-150000.79.1
fixed
golang-github-prometheus-node_exporter
suse enterprise desktop 15 SP7
1.5.0-150100.3.23.2
fixed
suse enterprise sap 15 SP7
1.5.0-150100.3.23.2
fixed
suse enterprise server 15 SP1
1.5.0-150100.3.23.2
fixed
suse enterprise server 15 SP2
1.5.0-150100.3.23.2
fixed
suse enterprise server 15 SP3
1.5.0-150100.3.23.2
fixed
suse enterprise server 15 SP4
1.5.0-150100.3.23.2
fixed
suse enterprise server 15 SP7
1.5.0-150100.3.23.2
fixed
podman
suse enterprise sap 15 SP3
3.4.7-150300.9.9.2
fixed
suse enterprise sap 15 SP4
3.4.7-150400.4.3.1
fixed
suse enterprise sap 15 SP5
4.4.4-150500.1.4
fixed
suse enterprise sap 15 SP6
4.8.3-150500.3.9.1
fixed
suse enterprise sap 15 SP7
4.9.5-150500.3.40.1
fixed
suse enterprise server 15 SP3
3.4.7-150300.9.9.2
fixed
suse enterprise server 15 SP4
3.4.7-150400.4.3.1
fixed
suse enterprise server 15 SP5
4.4.4-150500.1.4
fixed
suse enterprise server 15 SP6
4.8.3-150500.3.9.1
fixed
suse enterprise server 15 SP7
4.9.5-150500.3.40.1
fixed
podman-cni-config
suse enterprise sap 15 SP3
3.4.7-150300.9.9.2
fixed
suse enterprise sap 15 SP4
3.4.7-150400.4.3.1
fixed
suse enterprise sap 15 SP5
4.4.4-150500.1.4
fixed
suse enterprise server 15 SP3
3.4.7-150300.9.9.2
fixed
suse enterprise server 15 SP4
3.4.7-150400.4.3.1
fixed
suse enterprise server 15 SP5
4.4.4-150500.1.4
fixed
podman-docker
suse enterprise sap 15 SP4
3.4.7-150400.4.3.1
fixed
suse enterprise sap 15 SP5
4.4.4-150500.1.4
fixed
suse enterprise sap 15 SP6
4.8.3-150500.3.9.1
fixed
suse enterprise sap 15 SP7
4.9.5-150500.3.40.1
fixed
suse enterprise server 15 SP4
3.4.7-150400.4.3.1
fixed
suse enterprise server 15 SP5
4.4.4-150500.1.4
fixed
suse enterprise server 15 SP6
4.8.3-150500.3.9.1
fixed
suse enterprise server 15 SP7
4.9.5-150500.3.40.1
fixed
podman-remote
suse enterprise sap 15 SP4
3.4.7-150400.4.3.1
fixed
suse enterprise sap 15 SP5
4.4.4-150500.1.4
fixed
suse enterprise sap 15 SP6
4.8.3-150500.3.9.1
fixed
suse enterprise sap 15 SP7
4.9.5-150500.3.40.1
fixed
suse enterprise server 15 SP4
3.4.7-150400.4.3.1
fixed
suse enterprise server 15 SP5
4.4.4-150500.1.4
fixed
suse enterprise server 15 SP6
4.8.3-150500.3.9.1
fixed
suse enterprise server 15 SP7
4.9.5-150500.3.40.1
fixed
podmansh
suse enterprise sap 15 SP6
4.8.3-150500.3.9.1
fixed
suse enterprise sap 15 SP7
4.9.5-150500.3.40.1
fixed
suse enterprise server 15 SP6
4.8.3-150500.3.9.1
fixed
suse enterprise server 15 SP7
4.9.5-150500.3.40.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
buildah
RHEL 9
1:1.27.0-2.el9
fixed
buildah-tests
RHEL 9
1:1.27.0-2.el9
fixed
podman
RHEL 9
2:4.2.0-3.el9
fixed
podman-docker
RHEL 9
2:4.2.0-3.el9
fixed
podman-gvproxy
RHEL 9
2:4.2.0-3.el9
fixed
podman-plugins
RHEL 9
2:4.2.0-3.el9
fixed
podman-remote
RHEL 9
2:4.2.0-3.el9
fixed
podman-tests
RHEL 9
2:4.2.0-3.el9
fixed
References