Executive brief
A vulnerability in the Go SSH agent library can cause SSH clients to crash unexpectedly. This occurs when a client receives a specific success message while expecting a different type of data, leading to a service outage for the affected client. This could disrupt automated systems or remote management tools that rely on SSH for secure communication.
Technical details
A Reachable Assertion (CWE-617) exists in the golang.org/x/crypto/ssh/agent package. When an SSH client receives an SSH_AGENT_SUCCESS message while it is expecting a typed response, the library triggers a panic, leading to the immediate termination of the client process. This is a remote denial of service vulnerability that can be triggered without authentication if an attacker can influence the responses from an SSH agent. The issue is fixed in version 0.43.0 of the package.
Affected products
- Go crypto/ssh/agent < 0.43.0
Timeline
- 2025-11-13: disclosed
- 2025-11-14: advisory
References
- https://api.github.com/users/augustocesarperin
- https://github.com/augustocesarperin
- https://api.github.com/users/augustocesarperin/gists%7B/gist_id%7D
- https://api.github.com/users/augustocesarperin/repos
- https://avatars.githubusercontent.com/u/39884783?v=4
- https://api.github.com/users/augustocesarperin/events%7B/privacy%7D