CVE-2026-39830
cAdvisor 취약성 분석 및 완화

개요

CVE-2026-39830 is a denial-of-service vulnerability in Go's golang.org/x/crypto/ssh package where a malicious SSH peer can send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop indefinitely. The blocked goroutine cannot be released even by calling Close(), resulting in a resource leak per connection. All versions of golang.org/x/crypto before 0.52.0 are affected. The vulnerability was published on May 22, 2026, and carries a CVSS v3.1 base score of 9.1 (Critical) (pkg.go.dev, EUVD).

기술적 세부 사항

The root cause is classified as CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer). The Go SSH library's connection read loop processes incoming SSH messages, including global request responses, without discarding unsolicited ones. A malicious SSH peer — acting as either a client or server — can flood the internal response channel buffer with unsolicited global request responses, causing the goroutine handling the read loop to block permanently. Because the goroutine cannot be unblocked via Close(), each such connection results in a persistent goroutine and resource leak. The fix, introduced in version 0.52.0, discards unsolicited global responses rather than queuing them (pkg.go.dev, Go Issue, Go CL 781640).

영향

Successful exploitation allows an unauthenticated network attacker to cause a denial of service by hanging SSH connections and leaking goroutine resources on the affected server or client. Over multiple connections, this can exhaust system memory and goroutine limits, effectively crashing or rendering unresponsive any Go application using the golang.org/x/crypto/ssh package for SSH communication. Confidentiality impact is rated High by NVD (CVSS), though the primary real-world consequence is availability loss; there is no evidence of direct data exfiltration via this vector (pkg.go.dev, EUVD).

착취 단계

  1. Reconnaissance: Identify services built with Go that use golang.org/x/crypto/ssh versions prior to 0.52.0 — this includes SSH servers, clients, or any application embedding Go SSH functionality (e.g., Portainer, rclone, Pulumi Kubernetes provider).
  2. Establish SSH connection: Initiate a standard SSH connection to the target service. No credentials are required to begin the protocol handshake.
  3. Send unsolicited global request responses: During or after the SSH handshake, send a high volume of SSH SSH_MSG_REQUEST_SUCCESS or SSH_MSG_REQUEST_FAILURE messages (global request responses) that were never requested by the server.
  4. Fill internal buffer: The target's read loop goroutine attempts to queue these responses into an internal channel buffer. Once the buffer is full, the goroutine blocks indefinitely.
  5. Trigger resource leak: Repeat across multiple connections. Each blocked goroutine cannot be freed by Close(), causing cumulative goroutine and memory leaks that degrade or crash the target service (Go Issue, pkg.go.dev).

타협의 징후

  • Network: Unusual volume of SSH connections from a single source IP that do not complete normal authentication flows; connections that remain open indefinitely without activity.
  • Process/Runtime: Rapidly increasing goroutine count in Go application metrics (e.g., runtime.NumGoroutine() growing unboundedly); elevated memory consumption in SSH-serving Go processes.
  • Logs: SSH connection log entries showing connections established but never cleanly terminated; absence of normal disconnect or timeout log entries for established sessions.
  • System: Increasing file descriptor usage associated with the Go SSH process; system-level OOM (out-of-memory) events or process crashes in applications using golang.org/x/crypto/ssh (Go Issue, oss-sec).

완화 및 해결 방법

The primary remediation is to update golang.org/x/crypto to version 0.52.0 or later, which discards unsolicited global SSH responses instead of queuing them. Applications and distributions that bundle this package — including rclone, Portainer, Pulumi Kubernetes provider, and others — should update to their respective patched releases. As a network-level workaround, restrict SSH access to trusted peers only using firewall rules or network segmentation to reduce exposure until patching is complete (pkg.go.dev, Go CL 781640, Go CL 781664).

커뮤니티 반응

The Go security team disclosed the vulnerability via the golang-announce mailing list and published a Go vulnerability database entry (GO-2026-5017). The issue was also discussed on the oss-security mailing list. Multiple Linux distributions including openSUSE and Amazon Linux 2/2023 issued security advisories and package updates. Downstream projects such as rclone, Portainer, and Pulumi Kubernetes provider have released patched versions incorporating the fix (golang-announce, oss-sec, rclone changelog, Portainer release).

추가 자료


근원이 보고서는 AI를 사용하여 생성되었습니다.

관련 cAdvisor 취약점:

CVE ID

심각도

점수

기술

구성 요소 이름

CISA KEV 익스플로잇

수정 사항이 있습니다.

게시된 날짜

CVE-2026-39822HIGH7.8
  • Go logoGo
  • cluster-api-provider-vsphere-fips-1.14
아니요Jul 08, 2026
CVE-2026-56852HIGH7.5
  • cAdvisor logocAdvisor
  • backup-restore-operator-fips-10.0
아니요Jul 21, 2026
CVE-2026-46600HIGH7.5
  • cAdvisor logocAdvisor
  • docker-29
아니요Jul 21, 2026
CVE-2026-42505MEDIUM5.3
  • Go logoGo
  • eks-distro-1.34
아니요Jul 08, 2026
CVE-2026-41579LOW3.3
  • cAdvisor logocAdvisor
  • k8s-device-plugin
아니요Jul 01, 2026

무료 취약성 평가

클라우드 보안 태세를 벤치마킹합니다

9개의 보안 도메인에서 클라우드 보안 관행을 평가하여 위험 수준을 벤치마킹하고 방어의 허점을 식별합니다.

평가 요청

추가 Wiz 리소스

맞춤형 데모 받기

맞춤형 데모 신청하기

"내가 본 최고의 사용자 경험은 클라우드 워크로드에 대한 완전한 가시성을 제공합니다."
데이비드 에슬릭최고정보책임자(CISO)
"Wiz는 클라우드 환경에서 무슨 일이 일어나고 있는지 볼 수 있는 단일 창을 제공합니다."
아담 플레처최고 보안 책임자(CSO)
"우리는 Wiz가 무언가를 중요한 것으로 식별하면 실제로 중요하다는 것을 알고 있습니다."
그렉 포니아토프스키위협 및 취약성 관리 책임자