CVE-2021-43565: Input Validation

Published Dec 2, 2021
·
Updated

The x/crypto/ssh package before 0.0.0-20211202192323-5770296d904e of golang.org/x/crypto allows an attacker to panic an SSH server.

Other sources

The x/crypto/ssh package before 0.0.0-20211202192323-5770296d904e of golang.org/x/crypto allows an unauthenticated attacker to panic an SSH server.

There's an input validation flaw in golang.org/x/crypto's readCipherPacket() function. An unauthenticated attacker who sends an empty plaintext packet to a program linked with golang.org/x/crypto/ssh could cause a panic, potentially leading to denial of service.

Version v0.0.0-20211202192323-5770296d904e of golang.org/x/crypto fixes a vulnerability in the golang.org/x/crypto/ssh package which allowed unauthenticated clients to cause a panic in SSH servers.

Reference: https://github.com/golang/go/issues/49932

Red Hat

Affected Software

20 affected componentsFixes available
go/golang.org/x/crypto<0.0.0-20211202192323-5770296d904e
0.0.0-20211202192323-5770296d904e
redhat/kiali<0:v1.24.7.redhat1-1.el8
0:v1.24.7.redhat1-1.el8
redhat/cri-o<0:1.24.1-11.rhaos4.11.gitb0d2ef3.el8
0:1.24.1-11.rhaos4.11.gitb0d2ef3.el8
redhat/openshift<0:4.11.0-202207082037.p0.g9546431.assembly.stream.el8
0:4.11.0-202207082037.p0.g9546431.assembly.stream.el8
redhat/podman<2:4.0.2-6.rhaos4.11.el8
2:4.0.2-6.rhaos4.11.el8
redhat/mcg<0:5.10.0-72.el8
0:5.10.0-72.el8
redhat/golang.org/x/crypto 0.0.0-20211202192323<5770296
5770296
Golang ssh<0.0.0-20211202192323-5770296d904e
IBM Data Virtualization on Cloud Pak for Data<=3.0
IBM Watson Query on Cloud Pak for Data<=2.2
IBM Watson Query on Cloud Pak for Data<=2.1
IBM Watson Query on Cloud Pak for Data<=2.0
IBM Data Virtualization on Cloud Pak for Data<=1.8
IBM Data Virtualization on Cloud Pak for Data<=1.7
Microsoft cbl2 libcontainers-common 20210626-7
Microsoft cbl2 cf-cli 8.4.0-24
Microsoft cbl2 gh 2.13.0-24
Microsoft cbl2 cri-o 1.22.3-14
Microsoft cbl2 moby-buildx 0.7.1-24
Microsoft cbl2 gh 2.13.0-24

Event History

Dec 2, 2021
CVE Published
12:00 AM
Dec 9, 2021
Data Sourced
via Red Hat·06:12 PM
DescriptionSeverityAffected Software
Sep 6, 2022
CVE Published
via MITRE·05:03 PM
Data Sourced
via MITRE·05:03 PM
Description
Sep 7, 2022
Advisory Published
12:01 AM
Jul 23, 2024
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
SeverityAffected Software
Updated
via Microsoft·07:00 AM
DescriptionSeverity
Aug 15, 2025
Data Sourced
via IBM·03:29 PM
DescriptionAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2021-43565?

CVE-2021-43565 is a vulnerability in the x/crypto/ssh package of golang.org/x/crypto that allows an unauthenticated attacker to panic an SSH server.

2

What is the severity of CVE-2021-43565?

The severity of CVE-2021-43565 is high with a score of 7.5.

3

How does CVE-2021-43565 affect golang.org/x/crypto?

CVE-2021-43565 affects golang.org/x/crypto by allowing an unauthenticated attacker to panic an SSH server.

4

How do I fix CVE-2021-43565?

To fix CVE-2021-43565, update to version 0.0.0-20211202192323-5770296d904e or later of the x/crypto/ssh package from golang.org/x/crypto.

5

Are there any references for CVE-2021-43565?

Yes, you can find more information about CVE-2021-43565 at the following references: [CVE-2021-43565](https://www.cve.org/CVERecord?id=CVE-2021-43565), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2021-43565), [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=2030787), [Red Hat Security Advisory](https://access.redhat.com/errata/RHSA-2022:1276).

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203