Executive brief
A vulnerability in Go's SSH implementation allows a malicious peer to send specially crafted messages that can freeze (deadlock) an entire SSH connection after a channel has been established. This affects any application using Go's SSH library to accept remote connections, potentially causing denial of service and disconnection of legitimate users.
Technical details
The vulnerability is a deadlock condition in Go's SSH channel message handling (RFC 4254). A malicious SSH peer can craft specific channel messages that cause the connection to deadlock and become unresponsive. The root cause is improper handling of unrecognized channel messages—previously these were buffered and blocked instead of being explicitly handled or rejected. The fix implements proper RFC 4254 compliance by explicitly handling channel messages and global requests, while treating all other messages as protocol errors and tearing down the connection. Attack requires network access to an SSH server using vulnerable Go SSH library; no authentication bypass occurs but availability impact is high.
Affected products
- Go golang.org/x/crypto/ssh Prior to fix in CL/826524
Timeline
- 2026-09-02: disclosed
- 2026-09-02: patched: Fix applied via CL/826524