VDB

RHSA-2025%3A0653

RHSA-2025%3A0653 PUBLISHED CVSS 8.199999809265137 HIGH

A flaw was found in the x/crypto/ssh go library. Applications and libraries that misuse the ServerConfig.PublicKeyCallback callback may be susceptible to an authorization bypass. For example, an attacker may send public keys A and B and authenticate with A. PublicKeyCallback would be called only twice, first with A and then with B. A vulnerable application may then make authorization decisions based on key B, for which the attacker does not control the private key. The misuse of ServerConfig.PublicKeyCallback may cause an authorization bypass.

Risk Scores

CVSS 3.1
8.199999809265137
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N

Affected Products

VendorProductVersions
Red Hatopenshift4/ose-local-storage-mustgather-rhel9@sha256:1ab884f98586d2c1b14bcd03d3b120b7470b5903101ed9a4096d457e6ab36569_amd64 as a component of Red Hat OpenShift Container Platform 4.17*, openshift4/ose-local-storage-mustgather-rhel9@sha256:1ab884f98586d2c1b14bcd03d3b120b7470b5903101ed9a4096d457e6ab36569_amd64, *
Red Hatopenshift4/ose-local-storage-mustgather-rhel9@sha256:238c255a96e26f71d5b40628824a23048f4a3fd32f9fbfe5b94063b0c647ac11_ppc64le as a component of Red Hat OpenShift Container Platform 4.17*
Red Hatopenshift4/ose-vertical-pod-autoscaler-rhel9-operator@sha256:337f2d985957eccad95eab488ee5a9e6541015191400cee645f68b52edc1fa8e_ppc64le as a component of Red Hat OpenShift Container Platform 4.17*, *, *
Red Hatopenshift4/ose-local-storage-mustgather-rhel9@sha256:238c255a96e26f71d5b40628824a23048f4a3fd32f9fbfe5b94063b0c647ac11_ppc64le as a component of Red Hat OpenShift Container Platform 4.17openshift4/ose-local-storage-mustgather-rhel9@sha256:238c255a96e26f71d5b40628824a23048f4a3fd32f9fbfe5b94063b0c647ac11_ppc64le, *, *
Red Hatopenshift4/ose-local-storage-diskmaker-rhel9@sha256:b61e9281efb6c68d32c9becc5fe7d7fd601b04f7b2a5815e1c6bd38e69b5a1ae_amd64 as a component of Red Hat OpenShift Container Platform 4.17*, *, *
Red Hatopenshift4/ose-smb-csi-driver-rhel9-operator@sha256:9cee73a132fced89a5144050a24ba7e85da91c85244575e9628f369fe64664ec_s390x as a component of Red Hat OpenShift Container Platform 4.17*, openshift4/ose-smb-csi-driver-rhel9-operator@sha256:9cee73a132fced89a5144050a24ba7e85da91c85244575e9628f369fe64664ec_s390x, *
Red Hatopenshift4/ose-local-storage-mustgather-rhel9@sha256:03139664bf88cce6c7a1f28b36b38d05cdd1012cf69f670a66f696b1cd6191d7_arm64 as a component of Red Hat OpenShift Container Platform 4.17openshift4/ose-local-storage-mustgather-rhel9@sha256:03139664bf88cce6c7a1f28b36b38d05cdd1012cf69f670a66f696b1cd6191d7_arm64
Red Hatopenshift4/ose-local-storage-mustgather-rhel9@sha256:1ab884f98586d2c1b14bcd03d3b120b7470b5903101ed9a4096d457e6ab36569_amd64 as a component of Red Hat OpenShift Container Platform 4.17openshift4/ose-local-storage-mustgather-rhel9@sha256:1ab884f98586d2c1b14bcd03d3b120b7470b5903101ed9a4096d457e6ab36569_amd64
Red Hatopenshift4/ose-cloud-event-proxy-rhel9@sha256:9c8b3eed0a3385f54c6af67cb2bb48717c7fc34ad729545587271de329888aa5_ppc64le as a component of Red Hat OpenShift Container Platform 4.17openshift4/ose-cloud-event-proxy-rhel9@sha256:9c8b3eed0a3385f54c6af67cb2bb48717c7fc34ad729545587271de329888aa5_ppc64le
Red Hatopenshift4/ose-local-storage-mustgather-rhel9@sha256:6df974dd34bba7a40545655ae6eddf408d3247cd4e6c0f9af3293ebb21bfa303_s390x as a component of Red Hat OpenShift Container Platform 4.17*, *, *
Red Hatopenshift4/ose-cloud-event-proxy-rhel9@sha256:83a10ecb35b4a177481d7fa6a311b601b6ea96f2b4d85becad4cebc123ead0fc_arm64
Red Hatopenshift4/ose-cloud-event-proxy-rhel9@sha256:83a10ecb35b4a177481d7fa6a311b601b6ea96f2b4d85becad4cebc123ead0fc_arm64 as a component of Red Hat OpenShift Container Platform 4.17*, *, *
Red Hatopenshift4/ose-local-storage-diskmaker-rhel9@sha256:74d7d8b2546502c87fc4e67420e80895c3d02a5f817ef7ba54b7c5e4f719a18e_s390x as a component of Red Hat OpenShift Container Platform 4.17*, openshift4/ose-local-storage-diskmaker-rhel9@sha256:74d7d8b2546502c87fc4e67420e80895c3d02a5f817ef7ba54b7c5e4f719a18e_s390x, *
Red Hatopenshift4/ose-smb-csi-driver-rhel9-operator@sha256:82dc51f470dba32cb720a369d17d7359688db2bf872200250221f19e0f546dc7_amd64 as a component of Red Hat OpenShift Container Platform 4.17openshift4/ose-smb-csi-driver-rhel9-operator@sha256:82dc51f470dba32cb720a369d17d7359688db2bf872200250221f19e0f546dc7_amd64
Red Hatopenshift4/ose-cloud-event-proxy-rhel9@sha256:9c8b3eed0a3385f54c6af67cb2bb48717c7fc34ad729545587271de329888aa5_ppc64le as a component of Red Hat OpenShift Container Platform 4.17*, *, openshift4/ose-cloud-event-proxy-rhel9@sha256:9c8b3eed0a3385f54c6af67cb2bb48717c7fc34ad729545587271de329888aa5_ppc64le
Red Hatopenshift4/ose-local-storage-rhel9-operator@sha256:41ee609ac63866e22b18c311161c5b211da5dbaf504afec79662962eac283ad4_ppc64le as a component of Red Hat OpenShift Container Platform 4.17*, *, *
Red Hatopenshift4/ose-ptp-rhel9-operator@sha256:b9ba63d0a7a6930403bf4a19a70d449456219e0331134eafa97dfdfadeae0acd_ppc64le as a component of Red Hat OpenShift Container Platform 4.17openshift4/ose-ptp-rhel9-operator@sha256:b9ba63d0a7a6930403bf4a19a70d449456219e0331134eafa97dfdfadeae0acd_ppc64le
Red Hatopenshift4/ose-ptp-rhel9-operator@sha256:5c92b4acb8df7a117c3a92c4e93fc0304db985a4426ceb90c362bcca517f077c_arm64 as a component of Red Hat OpenShift Container Platform 4.17openshift4/ose-ptp-rhel9-operator@sha256:5c92b4acb8df7a117c3a92c4e93fc0304db985a4426ceb90c362bcca517f077c_arm64
Red Hatopenshift4/ose-vertical-pod-autoscaler-rhel9@sha256:bfc5730568927a5bcd9ac65f8907c7498bbafa1cffbef65d6299dddb748b2a7d_arm64 as a component of Red Hat OpenShift Container Platform 4.17*, openshift4/ose-vertical-pod-autoscaler-rhel9@sha256:bfc5730568927a5bcd9ac65f8907c7498bbafa1cffbef65d6299dddb748b2a7d_arm64, *
Red Hatopenshift4/ose-local-storage-diskmaker-rhel9@sha256:1c1418b4ab558ac00178c4aca51d7388c518c77e565b4fbb497706857237c184_ppc64le as a component of Red Hat OpenShift Container Platform 4.17openshift4/ose-local-storage-diskmaker-rhel9@sha256:1c1418b4ab558ac00178c4aca51d7388c518c77e565b4fbb497706857237c184_ppc64le

…and 58 more

Timeline

  • Jan 28, 2025 CVE Published
  • Apr 25, 2026 Distribution Patch
  • Apr 25, 2026 Distribution Patch
  • Apr 25, 2026 Security Advisory
  • Apr 25, 2026 Security Advisory
  • Apr 25, 2026 Security Advisory
  • Jul 19, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›