← Back

CVE-2026-39834

nvd nist
Published: May 22, 2026Modified: Jul 23, 2026

JSON object

Loading...
9.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Exploitability: 3.9 / Impact: 5.2
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

When writing data larger than 4GB in a single Write call on an SSH channel, an integer overflow in the internal payload size calculation caused the write loop to spin indefinitely, sending empty packets without making progress. The size comparison now uses int64 to prevent truncation.

Affected (1)

Products: Golang: Crypto
1 product
Crypto
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 0.52.0

References (4)

Source: security@golang.org
Issue Tracking
Source: security@golang.org
Issue Tracking
Source: security@golang.org
Mailing List
Source: security@golang.org
Vendor Advisory

Timeline

No history available yet.