VDB
RHSA-2025%3A3560
RHSA-2025%3A3560
PUBLISHED
CVSS 8.199999809265137 HIGH
A flaw was found in the x/crypto/ssh go library. Applications and libraries that misuse the ServerConfig.PublicKeyCallback callback may be susceptible to an authorization bypass. For example, an attacker may send public keys A and B and authenticate with A. PublicKeyCallback would be called only twice, first with A and then with B. A vulnerable application may then make authorization decisions based on key B, for which the attacker does not control the private key. The misuse of ServerConfig.PublicKeyCallback may cause an authorization bypass.
Risk Scores
CVSS 3.1
8.199999809265137
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | odf4/mcg-core-rhel9@sha256:8797421d8b1de01b8f797b4f7d31bd741c2dfa612c5de01bd34fe957476b2e91_s390x as a component of RHODF 4.14 for RHEL 9 | odf4/mcg-core-rhel9@sha256:8797421d8b1de01b8f797b4f7d31bd741c2dfa612c5de01bd34fe957476b2e91_s390x |
| Red Hat | odf4/ocs-client-rhel9-operator@sha256:d07a2e543f9d6fc673c89bba4ca4ef051dfc6c59a77868de9d8086ff9f923e88_arm64 as a component of RHODF 4.14 for RHEL 9 | odf4/ocs-client-rhel9-operator@sha256:d07a2e543f9d6fc673c89bba4ca4ef051dfc6c59a77868de9d8086ff9f923e88_arm64 |
| Red Hat | odf4/mcg-rhel9-operator@sha256:5c283756969496f6ae2d6ce8c7757b982831fc2ddacaf7279d5f6b571af0d37b_amd64 as a component of RHODF 4.14 for RHEL 9 | *, odf4/mcg-rhel9-operator@sha256:5c283756969496f6ae2d6ce8c7757b982831fc2ddacaf7279d5f6b571af0d37b_amd64, * |
| Red Hat | odf4/mcg-rhel9-operator@sha256:c5dc4d1542df960599b8f22218ef38bb849a806cc1d46d6e45a1a10255e7c8d3_s390x as a component of RHODF 4.14 for RHEL 9 | *, odf4/mcg-rhel9-operator@sha256:c5dc4d1542df960599b8f22218ef38bb849a806cc1d46d6e45a1a10255e7c8d3_s390x, * |
| Red Hat | odf4/odf-must-gather-rhel9@sha256:ecbf48f170244bb45337f0ee4757a0011cdf17bf56da49a4fc040d19fb3d54f5_ppc64le as a component of RHODF 4.14 for RHEL 9 | * |
| Red Hat | odf4/odf-multicluster-console-rhel9@sha256:6bedadb6458a45832d41e65799e1e28d23d5555a97929ec45e51c6b3e26644c2_s390x as a component of RHODF 4.14 for RHEL 9 | *, odf4/odf-multicluster-console-rhel9@sha256:6bedadb6458a45832d41e65799e1e28d23d5555a97929ec45e51c6b3e26644c2_s390x, * |
| Red Hat | odf4/odr-rhel9-operator@sha256:e45ec88513685282a85811e44a673d3d69bc2355d1730bbd4ac6b139b394935b_s390x as a component of RHODF 4.14 for RHEL 9 | odf4/odr-rhel9-operator@sha256:e45ec88513685282a85811e44a673d3d69bc2355d1730bbd4ac6b139b394935b_s390x |
| Red Hat | odf4/odf-multicluster-console-rhel9@sha256:b1ecb2d81cd162a1e78e50a287dc3df5b6d14bf5feb1c1c1cce629ba05aea2a8_amd64 as a component of RHODF 4.14 for RHEL 9 | *, odf4/odf-multicluster-console-rhel9@sha256:b1ecb2d81cd162a1e78e50a287dc3df5b6d14bf5feb1c1c1cce629ba05aea2a8_amd64, * |
| Red Hat | odf4/odf-csi-addons-operator-bundle@sha256:74342c8b5a6475d8f4192963321504c0167d287a890ba1b2ea1a70497f1f5dbe_ppc64le as a component of RHODF 4.14 for RHEL 9 | odf4/odf-csi-addons-operator-bundle@sha256:74342c8b5a6475d8f4192963321504c0167d287a890ba1b2ea1a70497f1f5dbe_ppc64le, *, * |
| Red Hat | odf4/mcg-rhel9-operator@sha256:d117e6618f677d3e9c98a0fc3f6cc3a60361cfdbb33506c2607561c8a8c94eda_ppc64le as a component of RHODF 4.14 for RHEL 9 | odf4/mcg-rhel9-operator@sha256:d117e6618f677d3e9c98a0fc3f6cc3a60361cfdbb33506c2607561c8a8c94eda_ppc64le |
| Red Hat | odf4/odf-must-gather-rhel9@sha256:2b6ac330ea876db86901b98f9ac1064c7ca21e3aba467c21dc570017d607f019_amd64 as a component of RHODF 4.14 for RHEL 9 | *, *, * |
| Red Hat | odf4/rook-ceph-rhel9-operator@sha256:2a51684ca0bbfa735fe89dac6f3ada1c078a00fa5722c4bc5f57e98f918e4122_s390x as a component of RHODF 4.14 for RHEL 9 | odf4/rook-ceph-rhel9-operator@sha256:2a51684ca0bbfa735fe89dac6f3ada1c078a00fa5722c4bc5f57e98f918e4122_s390x |
| Red Hat | odf4/odf-must-gather-rhel9@sha256:93b2febe6c5614c27286f6c7c49b445d310bfe55a345b27380fb4126067926bb_arm64 as a component of RHODF 4.14 for RHEL 9 | odf4/odf-must-gather-rhel9@sha256:93b2febe6c5614c27286f6c7c49b445d310bfe55a345b27380fb4126067926bb_arm64 |
| Red Hat | odf4/odf-operator-bundle@sha256:635ba6d730df39baadee79858f9320596d9cc33db5efa5d62066987ef986e457_s390x as a component of RHODF 4.14 for RHEL 9 | odf4/odf-operator-bundle@sha256:635ba6d730df39baadee79858f9320596d9cc33db5efa5d62066987ef986e457_s390x, *, * |
| Red Hat | odf4/ocs-rhel9-operator@sha256:f2cf1c7f5f0f01735c5a6b5fd7933cebfeeb6705e72eb396c69f1f2073c59ec3_s390x as a component of RHODF 4.14 for RHEL 9 | *, odf4/ocs-rhel9-operator@sha256:f2cf1c7f5f0f01735c5a6b5fd7933cebfeeb6705e72eb396c69f1f2073c59ec3_s390x, * |
| Red Hat | odf4/odf-csi-addons-rhel9-operator@sha256:f8c10ac336350424b46225e7e8ff5221075074c37063056e75d70e50b6fd4987_s390x as a component of RHODF 4.14 for RHEL 9 | odf4/odf-csi-addons-rhel9-operator@sha256:f8c10ac336350424b46225e7e8ff5221075074c37063056e75d70e50b6fd4987_s390x, *, * |
| Red Hat | odf4/mcg-core-rhel9@sha256:6ba1c8be2c7a4b2868711e5d602a794fc6f37a0b162e43a990e3f434cdf0044d_arm64 as a component of RHODF 4.14 for RHEL 9 | *, *, * |
| Red Hat | odf4/odf-cosi-sidecar-rhel9@sha256:d13b487c7fc20a394532ed4ef1a2ab29876a6178971277c39d378efaa4d1c2ec_ppc64le as a component of RHODF 4.14 for RHEL 9 | *, odf4/odf-cosi-sidecar-rhel9@sha256:d13b487c7fc20a394532ed4ef1a2ab29876a6178971277c39d378efaa4d1c2ec_ppc64le, * |
| Red Hat | odf4/ocs-rhel9-operator@sha256:bab9292348c97ea13be4ef8125107b6af68c16b862d9048589ed35cd883072f3_arm64 as a component of RHODF 4.14 for RHEL 9 | odf4/ocs-rhel9-operator@sha256:bab9292348c97ea13be4ef8125107b6af68c16b862d9048589ed35cd883072f3_arm64 |
…and 161 more
Timeline
- Apr 3, 2025 CVE Published
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Jul 13, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2025:3560 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2331720 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2333122 issue
- https://issues.redhat.com/browse/DFBUGS-1672 advisory
- https://issues.redhat.com/browse/DFBUGS-914 advisory
- https://issues.redhat.com/browse/DFBUGS-980 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_3560.json advisory
- https://access.redhat.com/security/cve/CVE-2024-45337 advisory
- https://www.cve.org/CVERecord?id=CVE-2024-45337 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-45337 advisory
- https://github.com/golang/crypto/commit/b4f1988a35dee11ec3e05d6bf3e90b695fbd8909 advisory
- https://go.dev/cl/635315 advisory
- https://go.dev/issue/70779 advisory
- https://groups.google.com/g/golang-announce/c/-nPEi39gI4Q/m/cGVPJCqdAQAJ advisory
- https://pkg.go.dev/vuln/GO-2024-3321 advisory
- https://access.redhat.com/security/cve/CVE-2024-45338 advisory
- https://www.cve.org/CVERecord?id=CVE-2024-45338 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-45338 advisory
- https://go.dev/cl/637536 advisory
…and 3 more