CVE-2026-56855

NameCVE-2026-56855
DescriptionPreviously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
golang-go.crypto (PTS)bookworm1:0.4.0-1vulnerable
trixie1:0.25.0-1vulnerable
forky1:0.55.0-1vulnerable
sid1:0.56.0-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
golang-go.cryptosource(unstable)1:0.56.0-1

Notes

https://github.com/golang/go/issues/81317
Fixed by: https://github.com/golang/crypto/commit/86efde54dc7069251a8b007026c500d28e4239ce (v0.56.0)

Search for package or bug name: Reporting problems