Skip to content

vendor: golang.org/x/crypto v0.56.0 - #7111

Open
thaJeztah wants to merge 1 commit into
moby:masterfrom
thaJeztah:bump_crypto2
Open

vendor: golang.org/x/crypto v0.56.0#7111
thaJeztah wants to merge 1 commit into
moby:masterfrom
thaJeztah:bump_crypto2

Conversation

@thaJeztah

Copy link
Copy Markdown
Member

full diff: golang/crypto@v0.55.0...v0.56.0

We have tagged version v0.56.0 of golang.org/x/crypto in order to address the following security issues:

  • ssh: prevent DoS on deadlocked established channel Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking. Thanks to Will Mortensen for reporting this issue. This is CVE-2026-56855 and Go issue https://go.dev/issue/81317.
  • ssh: prevent DoS on deadlocked undecided channel Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection. Thanks to Will Mortensen for reporting this issue. This is CVE-2026-78662 and Go issue https://go.dev/issue/81316.

full diff: golang/crypto@v0.55.0...v0.56.0

We have tagged version v0.56.0 of golang.org/x/crypto in
order to address the following security issues:
- ssh: prevent DoS on deadlocked established channel
  Previously, after a channel has been established, a
  malicious peer could send crafted messages that would
  deadlock the entire connection.
  Now, we handle all RFC 4254 channel messages; global
  requests are handled explicitly. Then, treat all other
  messages as a protocol error and tear the connection
  down instead of buffering and blocking.
  Thanks to Will Mortensen for reporting this issue.
  This is CVE-2026-56855 and Go issue https://go.dev/issue/81317.
- ssh: prevent DoS on deadlocked undecided channel
  Previously, a channel registered in the mux's chanList is
  not usable until it is established. A malicious peer was
  able flood the channel's incomingRequests, deadlocking the
  entire connection.
  Now, we add an atomic established state, set when a channel
  becomes usable. Until such a time, handlePacket drops every
  packet other than the open confirmation/failure, without
  blocking and without tearing down the connection.
  Thanks to Will Mortensen for reporting this issue.
  This is CVE-2026-78662 and Go issue https://go.dev/issue/81316.

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
@github-actions github-actions Bot added the area/dependencies Pull requests that update a dependency file label Sep 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant