Skip to content

fix: close SSH channel denial of service in x/crypto - #6

Merged
chen21019 merged 1 commit into
mainfrom
fix/ssh-channel-security-20260907
Sep 7, 2026
Merged

chen21019 merged 1 commit into
mainfrom
fix/ssh-channel-security-20260907

Conversation

@chen21019

Copy link
Copy Markdown

Upgrade the reviewed vendored golang.org/x/crypto module to v0.56.0 for CVE-2026-56855 and CVE-2026-78662. Preserve Docker Machine compatibility patches. Add tests at the actual SSH channel dispatch boundary for pre-establishment traffic, unexpected messages, and valid request/response behavior. Pin CI release artifacts to v0.39.7 and keep the existing OpenPGP applicability record aligned. Local Go race tests, focused SSH regression tests, vet, formatting and source validation pass; official CI remains required before release.

@chen21019
chen21019 requested a review from a team as a code owner September 7, 2026 15:15
@chen21019
chen21019 merged commit c396df5 into main Sep 7, 2026
5 checks passed
@chen21019
chen21019 deleted the fix/ssh-channel-security-20260907 branch September 7, 2026 15:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant