CVE-2025-47913

NameCVE-2025-47913
DescriptionSSH clients receiving SSH_AGENT_SUCCESS when expecting a typed response will panic and cause early termination of the client process.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
golang-go.crypto (PTS)bullseye1:0.0~git20201221.eec23a3-1vulnerable
bookworm1:0.4.0-1vulnerable
trixie1:0.25.0-1vulnerable
forky1:0.45.0-1fixed
sid1:0.47.0-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
golang-go.cryptosource(unstable)1:0.43.0-1

Notes

[bullseye] - golang-go.crypto <postponed> (Limited support, minor issue, follow bookworm DSAs/point-releases)
https://github.com/advisories/GHSA-56w8-48fp-6mgv
https://go-review.googlesource.com/c/crypto/+/700295
https://github.com/golang/go/issues/75178
Fixed by: https://github.com/golang/crypto/commit/559e062ce8bfd6a39925294620b50906ca2a6f95 (v0.43.0)

Search for package or bug name: Reporting problems