Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade rcloneUpgrade runfinch-finchUpgrade rclone-debuginfoUpgrade rclone-debugsource | Sep 30, 2026 | Sep 2, 2026 |
| Redhat_linux | — | Upgrade buildah-tests-debuginfoUpgrade buildah-debugsourceUpgrade buildah-debuginfoUpgrade buildah-testsNo solution existsUpgrade buildah | Sep 10, 2026 | Sep 2, 2026 |
| Rocky_linux | — | Upgrade buildah-debugsourceUpgrade buildahUpgrade buildah-testsUpgrade buildah-tests-debuginfoUpgrade buildah-debuginfo | Sep 28, 2026 | Sep 24, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub