CVE Vulnerabilities

CVE-2022-27191

Published: Mar 18, 2022 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey.

Affected Software

NameVendorStart VersionEnd Version
SshGolang*0.0.0-20220314234659-1baeb1ce4c0b (excluding)
OADP-1.1-RHEL-8RedHatoadp/oadp-velero-rhel8:1.1.1-20*
Openshift Serverless 1 on RHEL 8RedHatopenshift-serverless-clients-0:1.5.0-3.el8*
Red Hat Enterprise Linux 8RedHatcontainer-tools:rhel8-8070020220929222448.39077419*
Red Hat Enterprise Linux 8RedHatcontainer-tools:4.0-8070020220830101436.39077419*
Red Hat Enterprise Linux 9RedHatpodman-2:4.2.0-3.el9*
Red Hat Enterprise Linux 9RedHatbuildah-1:1.27.0-2.el9*
Red Hat OpenShift Container Platform 4.11RedHatcri-o-0:1.24.1-11.rhaos4.11.gitb0d2ef3.el8*
Red Hat OpenShift Container Platform 4.11RedHatopenshift4/ose-aws-ebs-csi-driver-rhel8:v4.11.0-202208020235.p0.g7564046.assembly.stream*
Red Hat OpenShift Container Platform 4.11RedHatopenshift4/ose-azure-disk-csi-driver-rhel8:v4.11.0-202208020235.p0.g0fe424e.assembly.stream*
Red Hat OpenShift Container Platform 4.11RedHatopenshift4/ose-azure-file-csi-driver-rhel8:v4.11.0-202208020235.p0.g67c3831.assembly.stream*
Red Hat OpenShift Container Platform 4.11RedHatopenshift4/ose-csi-driver-manila-rhel8:v4.11.0-202208020235.p0.g246ae15.assembly.stream*
Red Hat OpenShift Container Platform 4.11RedHatopenshift4/ose-csi-driver-nfs-rhel8:v4.11.0-202208020235.p0.gf144bb4.assembly.stream*
Red Hat OpenShift Container Platform 4.11RedHatopenshift4/ose-machine-api-provider-azure-rhel8:v4.11.0-202208020706.p0.g93b3f9e.assembly.stream*
Red Hat OpenShift Container Platform 4.11RedHatopenshift4/ose-openstack-cinder-csi-driver-rhel8:v4.11.0-202208020235.p0.g246ae15.assembly.stream*
Red Hat OpenShift Container Platform 4.11RedHatopenshift4/ose-openstack-cloud-controller-manager-rhel8:v4.11.0-202208020235.p0.g246ae15.assembly.stream*
Red Hat OpenShift Container Platform 4.11RedHatopenshift4/ose-vmware-vsphere-csi-driver-rhel8:v4.11.0-202208020235.p0.gd4721ba.assembly.stream*
Red Hat OpenShift Container Platform 4.11RedHatopenshift4/ose-vsphere-csi-driver-rhel8:v4.11.0-202208020235.p0.gd4721ba.assembly.stream*
Red Hat OpenShift Container Platform 4.11RedHatopenshift4/ose-installer:v4.11.0-202212070956.p0.g7e60d78.assembly.stream*
Red Hat OpenShift Container Platform 4.11RedHatopenshift4/ose-baremetal-installer-rhel8:v4.11.0-202212202214.p0.gd3fb15a.assembly.stream*
Red Hat OpenShift Container Platform 4.11RedHatopenshift4/ose-installer-artifacts:v4.11.0-202212202214.p0.gd3fb15a.assembly.stream*
Red Hat OpenShift Container Platform 4.11RedHatopenshift4-wincw/windows-machine-config-rhel8-operator:6.0.1-38*
Red Hat OpenShift Container Platform 4.12RedHatopenshift4/ose-node-feature-discovery:v4.12.0-202301042354.p0.g5e2696b.assembly.stream*
Red Hat OpenShift Container Platform 4.12RedHatopenshift4-wincw/windows-machine-config-rhel8-operator:7.0.0-22*
Red Hat OpenShift Container Platform 4.13RedHatopenshift-clients-0:4.13.0-202303241616.p0.g92b1a3d.assembly.stream.el9*
Red Hat OpenShift Container Platform 4.13RedHatopenshift4/ose-installer:v4.13.0-202305091542.p0.g44db7b2.assembly.stream*
Red Hat OpenShift Container Platform 4.13RedHatopenshift-clients-0:4.13.0-202305291355.p0.g1024efc.assembly.stream.el8*
RHACS-4.1-RHEL-8RedHatadvanced-cluster-security/rhacs-main-rhel8:4.1.0-13*
RHEL-7-CNV-4.11RedHatkubevirt-0:4.11.0-643.el7*
RHEL-8-CNV-4.11RedHatkubevirt-0:4.11.0-643.el8*
RHOSS-1.26-RHEL-8RedHatopenshift-serverless-1/client-kn-rhel8:1.5.0-3*
RHOSS-1.26-RHEL-8RedHatopenshift-serverless-1/eventing-apiserver-receive-adapter-rhel8:1.5.0-2*
RHOSS-1.26-RHEL-8RedHatopenshift-serverless-1/eventing-controller-rhel8:1.5.0-2*
RHOSS-1.26-RHEL-8RedHatopenshift-serverless-1/eventing-in-memory-channel-controller-rhel8:1.5.0-2*
RHOSS-1.26-RHEL-8RedHatopenshift-serverless-1/eventing-in-memory-channel-dispatcher-rhel8:1.5.0-2*
RHOSS-1.26-RHEL-8RedHatopenshift-serverless-1/eventing-kafka-broker-controller-rhel8:1.5.0-1*
RHOSS-1.26-RHEL-8RedHatopenshift-serverless-1/eventing-kafka-broker-dispatcher-rhel8:1.5.0-2*
RHOSS-1.26-RHEL-8RedHatopenshift-serverless-1/eventing-kafka-broker-post-install-rhel8:1.5.0-1*
RHOSS-1.26-RHEL-8RedHatopenshift-serverless-1/eventing-kafka-broker-receiver-rhel8:1.5.0-2*
RHOSS-1.26-RHEL-8RedHatopenshift-serverless-1/eventing-kafka-broker-webhook-rhel8:1.5.0-1*
RHOSS-1.26-RHEL-8RedHatopenshift-serverless-1/eventing-mtbroker-filter-rhel8:1.5.0-2*
RHOSS-1.26-RHEL-8RedHatopenshift-serverless-1/eventing-mtbroker-ingress-rhel8:1.5.0-2*
RHOSS-1.26-RHEL-8RedHatopenshift-serverless-1/eventing-mtchannel-broker-rhel8:1.5.0-2*
RHOSS-1.26-RHEL-8RedHatopenshift-serverless-1/eventing-mtping-rhel8:1.5.0-2*
RHOSS-1.26-RHEL-8RedHatopenshift-serverless-1/eventing-storage-version-migration-rhel8:1.5.0-2*
RHOSS-1.26-RHEL-8RedHatopenshift-serverless-1/eventing-webhook-rhel8:1.5.0-2*
RHOSS-1.26-RHEL-8RedHatopenshift-serverless-1/func-utils-rhel8:1.26.0-1*
RHOSS-1.26-RHEL-8RedHatopenshift-serverless-1/ingress-rhel8-operator:1.26.0-2*
RHOSS-1.26-RHEL-8RedHatopenshift-serverless-1/knative-rhel8-operator:1.26.0-2*
RHOSS-1.26-RHEL-8RedHatopenshift-serverless-1/kn-cli-artifacts-rhel8:1.5.0-4*
RHOSS-1.26-RHEL-8RedHatopenshift-serverless-1/kourier-control-rhel8:1.5.0-1*
RHOSS-1.26-RHEL-8RedHatopenshift-serverless-1/net-istio-controller-rhel8:1.5.0-1*
RHOSS-1.26-RHEL-8RedHatopenshift-serverless-1/net-istio-webhook-rhel8:1.5.0-1*
RHOSS-1.26-RHEL-8RedHatopenshift-serverless-1/serverless-operator-bundle:1.26.0-5*
RHOSS-1.26-RHEL-8RedHatopenshift-serverless-1/serverless-rhel8-operator:1.26.0-2*
RHOSS-1.26-RHEL-8RedHatopenshift-serverless-1/serving-activator-rhel8:1.5.0-2*
RHOSS-1.26-RHEL-8RedHatopenshift-serverless-1/serving-autoscaler-hpa-rhel8:1.5.0-2*
RHOSS-1.26-RHEL-8RedHatopenshift-serverless-1/serving-autoscaler-rhel8:1.5.0-2*
RHOSS-1.26-RHEL-8RedHatopenshift-serverless-1/serving-controller-rhel8:1.5.0-2*
RHOSS-1.26-RHEL-8RedHatopenshift-serverless-1/serving-domain-mapping-rhel8:1.5.0-2*
RHOSS-1.26-RHEL-8RedHatopenshift-serverless-1/serving-domain-mapping-webhook-rhel8:1.5.0-2*
RHOSS-1.26-RHEL-8RedHatopenshift-serverless-1/serving-queue-rhel8:1.5.0-2*
RHOSS-1.26-RHEL-8RedHatopenshift-serverless-1/serving-storage-version-migration-rhel8:1.5.0-2*
RHOSS-1.26-RHEL-8RedHatopenshift-serverless-1/serving-webhook-rhel8:1.5.0-2*
RHOSS-1.26-RHEL-8RedHatopenshift-serverless-1/svls-must-gather-rhel8:1.26.0-1*
RHOSS-1.26-RHEL-8RedHatopenshift-serverless-1-tech-preview/knative-client-plugin-event-sender-rhel8:1.5.0-1*
RHOSS-1.26-RHEL-8RedHatopenshift-serverless-1-tech-preview/logic-data-index-ephemeral-rhel8:1.26.0-5*
Golang-go.cryptoUbuntubionic*
Golang-go.cryptoUbuntufocal*
Golang-go.cryptoUbuntuimpish*
Golang-go.cryptoUbuntukinetic*
Golang-go.cryptoUbuntulunar*
Golang-go.cryptoUbuntumantic*
Golang-go.cryptoUbuntuoracular*
Golang-go.cryptoUbuntuplucky*
Golang-go.cryptoUbuntuxenial*
LxdUbuntuxenial*
SnapdUbuntutrusty*
SnapdUbuntuxenial*

References