VDB
RHSA-2025:0445
RHSA-2025:0445
PUBLISHED
CVSS 8.199999809265137 HIGH
A flaw was found in the x/crypto/ssh go library. Applications and libraries that misuse the ServerConfig.PublicKeyCallback callback may be susceptible to an authorization bypass. For example, an attacker may send public keys A and B and authenticate with A. PublicKeyCallback would be called only twice, first with A and then with B. A vulnerable application may then make authorization decisions based on key B, for which the attacker does not control the private key. The misuse of ServerConfig.PublicKeyCallback may cause an authorization bypass.
Risk Scores
CVSS 3.1
8.199999809265137
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | registry.redhat.io/rhtpa/rhtpa-trustification-service-rhel9@sha256:eb2e0b1003ef77c39b28fe9fbe2ca8141aa72160bdcd7d55eddac2c16629d7c4_amd64 as a component of Red Hat Trusted Profile Analyzer 1.2 | |
| Red Hat | registry.redhat.io/rhtpa/rhtpa-trustification-service-rhel9@sha256:eb2e0b1003ef77c39b28fe9fbe2ca8141aa72160bdcd7d55eddac2c16629d7c4_amd64 as a component of Red Hat Trusted Profile Analyzer 1.2 | *, registry.redhat.io/rhtpa/rhtpa-trustification-service-rhel9@sha256:eb2e0b1003ef77c39b28fe9fbe2ca8141aa72160bdcd7d55eddac2c16629d7c4_amd64 |
| Red Hat | registry.redhat.io/rhtpa/rhtpa-trustification-service-rhel9@sha256:eb2e0b1003ef77c39b28fe9fbe2ca8141aa72160bdcd7d55eddac2c16629d7c4_amd64 as a component of Red Hat Trusted Profile Analyzer 1.2 | *, *, * |
Timeline
- Jan 20, 2025 CVE Published
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- May 15, 2026 Security Advisory
- May 15, 2026 Security Advisory
- Jul 19, 2026 CVE Updated
- Jul 19, 2026 Distribution Patch
References
- https://issues.redhat.com/browse/TC-1817 advisory
- https://issues.redhat.com/browse/TC-2089 advisory
- https://issues.redhat.com/browse/TC-2097 advisory
- https://access.redhat.com/security/cve/CVE-2024-45337 advisory
- https://access.redhat.com/security/cve/CVE-2024-45338 advisory
- https://go.dev/issue/70779 advisory
- https://go.dev/cl/637536 advisory
- https://pkg.go.dev/vuln/GO-2024-3333 advisory
- https://github.com/go-git/go-git/security/advisories/GHSA-v725-9546-7q7m advisory
- https://github.com/go-git/go-git/security/advisories/GHSA-r9px-m959-cxf4 advisory
- https://access.redhat.com/errata/RHSA-2025:0445 advisory
- https://issues.redhat.com/browse/TC-2076 advisory
- https://access.redhat.com/security/cve/CVE-2025-21614 advisory
- https://access.redhat.com/security/updates/classification/ advisory
- https://www.cve.org/CVERecord?id=CVE-2024-45337 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-45337 advisory
- https://go.dev/issue/70906 advisory
- https://www.cve.org/CVERecord?id=CVE-2025-21613 advisory
- https://pkg.go.dev/vuln/GO-2025-3368 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-21614 advisory
…and 19 more