VDB

RHSA-2025%3A1849

RHSA-2025%3A1849 PUBLISHED CVSS 8.199999809265137 HIGH

A flaw was found in the x/crypto/ssh go library. Applications and libraries that misuse the ServerConfig.PublicKeyCallback callback may be susceptible to an authorization bypass. For example, an attacker may send public keys A and B and authenticate with A. PublicKeyCallback would be called only twice, first with A and then with B. A vulnerable application may then make authorization decisions based on key B, for which the attacker does not control the private key. The misuse of ServerConfig.PublicKeyCallback may cause an authorization bypass.

Risk Scores

CVSS 3.1
8.199999809265137
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N

Affected Products

VendorProductVersions
Red Hatregistry.redhat.io/rhtas/trillian-createdb-rhel9@sha256:2af38a2b19950b8c97d3e05b37f9dd10fa52cc5513379da2e0abc11b9e41eecd_amd64 as a component of Red Hat Trusted Artifact Signer 1.1registry.redhat.io/rhtas/trillian-createdb-rhel9@sha256:2af38a2b19950b8c97d3e05b37f9dd10fa52cc5513379da2e0abc11b9e41eecd_amd64
Red Hatregistry.redhat.io/rhtas/fulcio-createcerts-rhel9@sha256:ecc2df433b70ebb55942b3787293a87b280f7c734149547c7a9db85d0f1cc698_amd64 as a component of Red Hat Trusted Artifact Signer 1.1registry.redhat.io/rhtas/fulcio-createcerts-rhel9@sha256:ecc2df433b70ebb55942b3787293a87b280f7c734149547c7a9db85d0f1cc698_amd64
Red Hatregistry.redhat.io/rhtas/ctlog-managectroots-rhel9@sha256:eab52da98a670f44bb74bd5612eaf274f1699a9c9ab64bd5dd96f8c340188b0c_amd64 as a component of Red Hat Trusted Artifact Signer 1.1registry.redhat.io/rhtas/ctlog-managectroots-rhel9@sha256:eab52da98a670f44bb74bd5612eaf274f1699a9c9ab64bd5dd96f8c340188b0c_amd64
Red Hatregistry.redhat.io/rhtas/tuf-server-rhel9@sha256:16d4ccca29c5b0adae1627f9bbda217a9a0462a4fad32c1b48cce91d400272d3_amd64 as a component of Red Hat Trusted Artifact Signer 1.1registry.redhat.io/rhtas/tuf-server-rhel9@sha256:16d4ccca29c5b0adae1627f9bbda217a9a0462a4fad32c1b48cce91d400272d3_amd64
Red Hatregistry.redhat.io/rhtas/trillian-createdb-rhel9@sha256:2af38a2b19950b8c97d3e05b37f9dd10fa52cc5513379da2e0abc11b9e41eecd_amd64 as a component of Red Hat Trusted Artifact Signer 1.1registry.redhat.io/rhtas/trillian-createdb-rhel9@sha256:2af38a2b19950b8c97d3e05b37f9dd10fa52cc5513379da2e0abc11b9e41eecd_amd64
Red Hatregistry.redhat.io/rhtas/fulcio-createcerts-rhel9@sha256:ecc2df433b70ebb55942b3787293a87b280f7c734149547c7a9db85d0f1cc698_amd64 as a component of Red Hat Trusted Artifact Signer 1.1registry.redhat.io/rhtas/fulcio-createcerts-rhel9@sha256:ecc2df433b70ebb55942b3787293a87b280f7c734149547c7a9db85d0f1cc698_amd64
Red Hatregistry.redhat.io/rhtas/ctlog-managectroots-rhel9@sha256:eab52da98a670f44bb74bd5612eaf274f1699a9c9ab64bd5dd96f8c340188b0c_amd64 as a component of Red Hat Trusted Artifact Signer 1.1*
Red Hatregistry.redhat.io/rhtas/createctconfig-rhel9@sha256:2615696d76ff38653d5b05f6fd6fc4dad9e2269cbfcc6ea8a8e1e7b887f2e98b_amd64 as a component of Red Hat Trusted Artifact Signer 1.1registry.redhat.io/rhtas/createctconfig-rhel9@sha256:2615696d76ff38653d5b05f6fd6fc4dad9e2269cbfcc6ea8a8e1e7b887f2e98b_amd64
Red Hatregistry.redhat.io/rhtas/tuf-server-rhel9@sha256:16d4ccca29c5b0adae1627f9bbda217a9a0462a4fad32c1b48cce91d400272d3_amd64 as a component of Red Hat Trusted Artifact Signer 1.1*
Red Hatregistry.redhat.io/rhtas/createctconfig-rhel9@sha256:2615696d76ff38653d5b05f6fd6fc4dad9e2269cbfcc6ea8a8e1e7b887f2e98b_amd64 as a component of Red Hat Trusted Artifact Signer 1.1registry.redhat.io/rhtas/createctconfig-rhel9@sha256:2615696d76ff38653d5b05f6fd6fc4dad9e2269cbfcc6ea8a8e1e7b887f2e98b_amd64

Timeline

  • Feb 25, 2025 CVE Published
  • Apr 25, 2026 Distribution Patch
  • Apr 25, 2026 Distribution Patch
  • Apr 25, 2026 Security Advisory
  • Apr 25, 2026 Security Advisory
  • Apr 30, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›