VDB
RHSA-2025%3A0649
RHSA-2025%3A0649
PUBLISHED
CVSS 8.199999809265137 HIGH
A flaw was found in the x/crypto/ssh go library. Applications and libraries that misuse the ServerConfig.PublicKeyCallback callback may be susceptible to an authorization bypass. For example, an attacker may send public keys A and B and authenticate with A. PublicKeyCallback would be called only twice, first with A and then with B. A vulnerable application may then make authorization decisions based on key B, for which the attacker does not control the private key. The misuse of ServerConfig.PublicKeyCallback may cause an authorization bypass.
Risk Scores
CVSS 3.1
8.199999809265137
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift4/ose-kubernetes-nmstate-handler-rhel9@sha256:a827e2b3895e5edc20a8a26ee32bfab9b0ea448cd884b599fffcd673054b8048_s390x as a component of Red Hat OpenShift Container Platform 4.16 | openshift4/ose-kubernetes-nmstate-handler-rhel9@sha256:a827e2b3895e5edc20a8a26ee32bfab9b0ea448cd884b599fffcd673054b8048_s390x, *, * |
| Red Hat | openshift4/ose-baremetal-cluster-api-controllers-rhel9@sha256:fc3cea89aab6d2df854fc49db3ea39431442376d0e485b3f5c12893fc0c99315_ppc64le as a component of Red Hat OpenShift Container Platform 4.16 | *, *, * |
| Red Hat | openshift4/ptp-must-gather-rhel9@sha256:f6ffc587673dca8a96d4fe60c4e172ca0ba41426ffe58def1b19e1f844278c83_amd64 as a component of Red Hat OpenShift Container Platform 4.16 | openshift4/ptp-must-gather-rhel9@sha256:f6ffc587673dca8a96d4fe60c4e172ca0ba41426ffe58def1b19e1f844278c83_amd64, *, * |
| golang | ||
| Red Hat | openshift4/ose-baremetal-cluster-api-controllers-rhel9@sha256:e0337f476b9b770056b98f2a1379fea8f49a920852b05c3f46b3a27b5271e678_arm64 as a component of Red Hat OpenShift Container Platform 4.16 | *, *, * |
| Red Hat | openshift4/ose-baremetal-cluster-api-controllers-rhel9@sha256:fc3cea89aab6d2df854fc49db3ea39431442376d0e485b3f5c12893fc0c99315_ppc64le as a component of Red Hat OpenShift Container Platform 4.16 | * |
| Red Hat | openshift4/kubernetes-nmstate-rhel9-operator@sha256:097aca13e371ba6c768feebe748174e9f6c8cf374d15205cf6c114e0bb3a6cb9_arm64 as a component of Red Hat OpenShift Container Platform 4.16 | * |
| Red Hat | openshift4/ose-ptp-rhel9@sha256:74ccd531b29ab1b8edbdeacfad1d3e185befde48a9b3c48d561d0e668e7b2f53_ppc64le as a component of Red Hat OpenShift Container Platform 4.16 | openshift4/ose-ptp-rhel9@sha256:74ccd531b29ab1b8edbdeacfad1d3e185befde48a9b3c48d561d0e668e7b2f53_ppc64le |
| Red Hat | openshift4/ose-ptp-rhel9@sha256:7d4d05fe176ed5215ad6332464885df4e22d0dc0cd738e229b694bc82a293f48_amd64 as a component of Red Hat OpenShift Container Platform 4.16 | openshift4/ose-ptp-rhel9@sha256:7d4d05fe176ed5215ad6332464885df4e22d0dc0cd738e229b694bc82a293f48_amd64 |
| Red Hat | openshift4/ose-ptp-rhel9@sha256:0e59c30692d15a083e1db09b8743b1da4540f46a6ffd1a1a0711af68ae1c7e9d_arm64 as a component of Red Hat OpenShift Container Platform 4.16 | *, *, * |
| Red Hat | openshift4/kubernetes-nmstate-rhel9-operator@sha256:097aca13e371ba6c768feebe748174e9f6c8cf374d15205cf6c114e0bb3a6cb9_arm64 as a component of Red Hat OpenShift Container Platform 4.16 | *, openshift4/kubernetes-nmstate-rhel9-operator@sha256:097aca13e371ba6c768feebe748174e9f6c8cf374d15205cf6c114e0bb3a6cb9_arm64, * |
| Red Hat | openshift4/ptp-must-gather-rhel9@sha256:f6ffc587673dca8a96d4fe60c4e172ca0ba41426ffe58def1b19e1f844278c83_amd64 as a component of Red Hat OpenShift Container Platform 4.16 | openshift4/ptp-must-gather-rhel9@sha256:f6ffc587673dca8a96d4fe60c4e172ca0ba41426ffe58def1b19e1f844278c83_amd64 |
| Red Hat | openshift4/ose-ptp-rhel9-operator@sha256:5c282cff9756b5d4c2e277f0202a7e2faa3e4a6f53db76a2f21dd03a6dd0eef1_ppc64le as a component of Red Hat OpenShift Container Platform 4.16 | openshift4/ose-ptp-rhel9-operator@sha256:5c282cff9756b5d4c2e277f0202a7e2faa3e4a6f53db76a2f21dd03a6dd0eef1_ppc64le |
| Red Hat | openshift4/ose-cloud-event-proxy-rhel9@sha256:9e94a37d92415bea3b9c64f8227df1d048f36d3fc26ecc92400c0f3abecc6baf_arm64 as a component of Red Hat OpenShift Container Platform 4.16 | *, *, openshift4/ose-cloud-event-proxy-rhel9@sha256:9e94a37d92415bea3b9c64f8227df1d048f36d3fc26ecc92400c0f3abecc6baf_arm64 |
| Red Hat | openshift4/ose-cloud-event-proxy-rhel9@sha256:b18a781f76312753a80b16735e99900f1902f877730ed530f89d6f0b6653cf05_amd64 as a component of Red Hat OpenShift Container Platform 4.16 | * |
| Red Hat | openshift4/ose-cloud-event-proxy-rhel9@sha256:9e94a37d92415bea3b9c64f8227df1d048f36d3fc26ecc92400c0f3abecc6baf_arm64 as a component of Red Hat OpenShift Container Platform 4.16 | openshift4/ose-cloud-event-proxy-rhel9@sha256:9e94a37d92415bea3b9c64f8227df1d048f36d3fc26ecc92400c0f3abecc6baf_arm64 |
| Red Hat | openshift4/ose-kubernetes-nmstate-handler-rhel9@sha256:536f4e894aab2bf6e53a34e0a061ad8bfd0e1957148060a86c722e1e30d5c46e_ppc64le as a component of Red Hat OpenShift Container Platform 4.16 | openshift4/ose-kubernetes-nmstate-handler-rhel9@sha256:536f4e894aab2bf6e53a34e0a061ad8bfd0e1957148060a86c722e1e30d5c46e_ppc64le, *, * |
| Red Hat | openshift4/ose-baremetal-cluster-api-controllers-rhel9@sha256:50d650b8e58cc450ecd5276448ed1300164b657b3679094c11a84cf81135f319_s390x as a component of Red Hat OpenShift Container Platform 4.16 | openshift4/ose-baremetal-cluster-api-controllers-rhel9@sha256:50d650b8e58cc450ecd5276448ed1300164b657b3679094c11a84cf81135f319_s390x |
| Red Hat | openshift4/ose-ptp-rhel9-operator@sha256:c9d94178cd733ef277ac3d7a231376f0e0629729f4879e51a7d662cbaaa24d02_amd64 as a component of Red Hat OpenShift Container Platform 4.16 | openshift4/ose-ptp-rhel9-operator@sha256:c9d94178cd733ef277ac3d7a231376f0e0629729f4879e51a7d662cbaaa24d02_amd64 |
| Red Hat | openshift4/ose-kubernetes-nmstate-handler-rhel9@sha256:4d1a02f8e3e6ae24d8757c7efeeb9f2f3eb79b5afa85c36bb57eca77c4506865_amd64 as a component of Red Hat OpenShift Container Platform 4.16 | openshift4/ose-kubernetes-nmstate-handler-rhel9@sha256:4d1a02f8e3e6ae24d8757c7efeeb9f2f3eb79b5afa85c36bb57eca77c4506865_amd64 |
…and 30 more
Timeline
- Jan 29, 2025 CVE Published
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Jul 19, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2025:0649 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2331720 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2333122 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_0649.json advisory
- https://access.redhat.com/security/cve/CVE-2024-45337 advisory
- https://www.cve.org/CVERecord?id=CVE-2024-45337 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-45337 advisory
- https://github.com/golang/crypto/commit/b4f1988a35dee11ec3e05d6bf3e90b695fbd8909 advisory
- https://go.dev/cl/635315 advisory
- https://go.dev/issue/70779 advisory
- https://groups.google.com/g/golang-announce/c/-nPEi39gI4Q/m/cGVPJCqdAQAJ advisory
- https://pkg.go.dev/vuln/GO-2024-3321 advisory
- https://access.redhat.com/security/cve/CVE-2024-45338 advisory
- https://www.cve.org/CVERecord?id=CVE-2024-45338 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-45338 advisory
- https://go.dev/cl/637536 advisory
- https://go.dev/issue/70906 advisory
- https://groups.google.com/g/golang-announce/c/wSCRmFnNmPA/m/Lvcd0mRMAwAJ advisory
- https://pkg.go.dev/vuln/GO-2024-3333 advisory