VDB

RHSA-2025%3A0839

RHSA-2025%3A0839 PUBLISHED CVSS 8.199999809265137 HIGH

A flaw was found in the x/crypto/ssh go library. Applications and libraries that misuse the ServerConfig.PublicKeyCallback callback may be susceptible to an authorization bypass. For example, an attacker may send public keys A and B and authenticate with A. PublicKeyCallback would be called only twice, first with A and then with B. A vulnerable application may then make authorization decisions based on key B, for which the attacker does not control the private key. The misuse of ServerConfig.PublicKeyCallback may cause an authorization bypass.

Risk Scores

CVSS 3.1
8.199999809265137
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N

Affected Products

VendorProductVersions
Red Hatopenshift4/metallb-rhel9-operator@sha256:e49f1cc2d8ac5e5bf8c2084b4450adf9c344707acc5019577da47226576c23b0_ppc64le as a component of Red Hat OpenShift Container Platform 4.14openshift4/metallb-rhel9-operator@sha256:e49f1cc2d8ac5e5bf8c2084b4450adf9c344707acc5019577da47226576c23b0_ppc64le
Red Hatopenshift4/ose-ptp-rhel9@sha256:4f0eda87ad358cf58e76c2b827d195dc5f6751c71f5e827de66ff8a331bdf55c_amd64 as a component of Red Hat OpenShift Container Platform 4.14openshift4/ose-ptp-rhel9@sha256:4f0eda87ad358cf58e76c2b827d195dc5f6751c71f5e827de66ff8a331bdf55c_amd64
Red Hatopenshift4/ose-sriov-network-config-daemon@sha256:40c233ee4ceb776cef71993f17476a90da1e2c2f2a9b5618fc0619b1afb32a62_ppc64le as a component of Red Hat OpenShift Container Platform 4.14openshift4/ose-sriov-network-config-daemon@sha256:40c233ee4ceb776cef71993f17476a90da1e2c2f2a9b5618fc0619b1afb32a62_ppc64le, *, *
Red Hatopenshift4/ose-local-storage-operator@sha256:070b745899d04927ccc5a6d5fb5c1a0f77f22f016da5ba4985bced96b23f0ab9_ppc64le as a component of Red Hat OpenShift Container Platform 4.14openshift4/ose-local-storage-operator@sha256:070b745899d04927ccc5a6d5fb5c1a0f77f22f016da5ba4985bced96b23f0ab9_ppc64le
Red Hatopenshift4/ose-sriov-network-operator@sha256:03e7542d6295991d7214aa18918fd64f2e055c9402e67b52c707ee979e7f8c83_arm64 as a component of Red Hat OpenShift Container Platform 4.14openshift4/ose-sriov-network-operator@sha256:03e7542d6295991d7214aa18918fd64f2e055c9402e67b52c707ee979e7f8c83_arm64
Red Hatopenshift4/ingress-node-firewall-rhel9-operator@sha256:bd5ec8d4fc25634a6b4bc135e3bfb3033a2435f97749c564371ca67b585fe702_arm64 as a component of Red Hat OpenShift Container Platform 4.14*
Red Hatopenshift4/ose-gcp-filestore-csi-driver-rhel8@sha256:61df7938ea08ee7cdd121451052585f753532e03058ff970e3ae91e4c1920bb0_ppc64le as a component of Red Hat OpenShift Container Platform 4.14openshift4/ose-gcp-filestore-csi-driver-rhel8@sha256:61df7938ea08ee7cdd121451052585f753532e03058ff970e3ae91e4c1920bb0_ppc64le
Red Hatopenshift4/ose-clusterresourceoverride-rhel8@sha256:f6e444c6285049fc4e8462cd40005fe6a14cb0ff049ff4c2c1cf049e0aa1e97a_arm64 as a component of Red Hat OpenShift Container Platform 4.14*, openshift4/ose-clusterresourceoverride-rhel8@sha256:f6e444c6285049fc4e8462cd40005fe6a14cb0ff049ff4c2c1cf049e0aa1e97a_arm64, *
Red Hatopenshift4/ose-secrets-store-csi-driver-rhel8@sha256:cb71ac8032f26d4b15391ffdf81e3a6126a3c55df64e3291aabc25d0760d1309_arm64 as a component of Red Hat OpenShift Container Platform 4.14*, *, *
Red Hatopenshift4/ose-secrets-store-csi-mustgather-rhel8@sha256:f6d0339cfc10f0c7bfc27c4c470431b0505fb840ca0335c33e95a59eaa734eba_arm64 as a component of Red Hat OpenShift Container Platform 4.14*
Red Hatopenshift4/ose-kubernetes-nmstate-handler-rhel9@sha256:36b1a2c7bfb53432d6ee4869132f40c31cc046ba1128aa1c504acbcd68daea8e_amd64 as a component of Red Hat OpenShift Container Platform 4.14*, *, *
Red Hatopenshift4/ose-vertical-pod-autoscaler-rhel8-operator@sha256:3a53cb230a0bd81584e6a02ffe1aaf7472f32d174437ea29b31a9f66f8dbaae7_s390x as a component of Red Hat OpenShift Container Platform 4.14openshift4/ose-vertical-pod-autoscaler-rhel8-operator@sha256:3a53cb230a0bd81584e6a02ffe1aaf7472f32d174437ea29b31a9f66f8dbaae7_s390x, *, *
Red Hatopenshift4/ose-cluster-kube-descheduler-rhel8-operator@sha256:9ff903ec54cfa8215583d32173834b420a6013d97fb29b63f47fcaaa43e51f24_amd64 as a component of Red Hat OpenShift Container Platform 4.14*
Red Hatopenshift4/kubernetes-nmstate-rhel9-operator@sha256:e9ddf45b0ec8756f414aab6caf9c577f378de1f796604fc24c8c7390869e1d00_ppc64le as a component of Red Hat OpenShift Container Platform 4.14openshift4/kubernetes-nmstate-rhel9-operator@sha256:e9ddf45b0ec8756f414aab6caf9c577f378de1f796604fc24c8c7390869e1d00_ppc64le, *, *
Red Hatopenshift4/ose-node-feature-discovery@sha256:28fcce26712c80baac85c3d62fbfd3a8ae49d2a7a0e8c16dabed978f6eb8e0eb_s390x as a component of Red Hat OpenShift Container Platform 4.14*, openshift4/ose-node-feature-discovery@sha256:28fcce26712c80baac85c3d62fbfd3a8ae49d2a7a0e8c16dabed978f6eb8e0eb_s390x, *
Red Hatopenshift4/ose-helm-operator@sha256:85e6bd5ea029fc506aaf9a8de2553c3342a917439d4e68fcb6baf78eedc30e7e_ppc64le as a component of Red Hat OpenShift Container Platform 4.14*
Red Hatopenshift4/ose-cluster-nfd-operator@sha256:8f8a2896c20a83313378edbfef82dbe6edbf7d9cb6071fc37a2863742c245927_arm64 as a component of Red Hat OpenShift Container Platform 4.14openshift4/ose-cluster-nfd-operator@sha256:8f8a2896c20a83313378edbfef82dbe6edbf7d9cb6071fc37a2863742c245927_arm64, *, *
Red Hatopenshift4/ose-cluster-capacity@sha256:d001516f4d74df138839fed4fb1fa672f78c4ecb27c07140088f90afa3dea857_ppc64le as a component of Red Hat OpenShift Container Platform 4.14*, *, openshift4/ose-cluster-capacity@sha256:d001516f4d74df138839fed4fb1fa672f78c4ecb27c07140088f90afa3dea857_ppc64le
Red Hatopenshift4/ose-ansible-operator@sha256:21f3f95fbd412003d6fdf2a36220e48841515905983730fdd8faedb2237db6b5_s390x as a component of Red Hat OpenShift Container Platform 4.14openshift4/ose-ansible-operator@sha256:21f3f95fbd412003d6fdf2a36220e48841515905983730fdd8faedb2237db6b5_s390x, *, *

…and 315 more

Timeline

  • Feb 6, 2025 CVE Published
  • Apr 25, 2026 Distribution Patch
  • Apr 25, 2026 Distribution Patch
  • Apr 25, 2026 Security Advisory
  • Apr 25, 2026 Security Advisory
  • Apr 25, 2026 Security Advisory
  • Jul 19, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›