CVE-2026-39830:
cAdvisor 취약성 분석 및 완화
개요
CVE-2026-39830 is a denial-of-service vulnerability in Go's golang.org/x/crypto/ssh package where a malicious SSH peer can send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop indefinitely. The blocked goroutine cannot be released even by calling Close(), resulting in a resource leak per connection. All versions of golang.org/x/crypto before 0.52.0 are affected. The vulnerability was published on May 22, 2026, and carries a CVSS v3.1 base score of 9.1 (Critical) (pkg.go.dev, EUVD).
기술적 세부 사항
The root cause is classified as CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer). The Go SSH library's connection read loop processes incoming SSH messages, including global request responses, without discarding unsolicited ones. A malicious SSH peer — acting as either a client or server — can flood the internal response channel buffer with unsolicited global request responses, causing the goroutine handling the read loop to block permanently. Because the goroutine cannot be unblocked via Close(), each such connection results in a persistent goroutine and resource leak. The fix, introduced in version 0.52.0, discards unsolicited global responses rather than queuing them (pkg.go.dev, Go Issue, Go CL 781640).
영향
Successful exploitation allows an unauthenticated network attacker to cause a denial of service by hanging SSH connections and leaking goroutine resources on the affected server or client. Over multiple connections, this can exhaust system memory and goroutine limits, effectively crashing or rendering unresponsive any Go application using the golang.org/x/crypto/ssh package for SSH communication. Confidentiality impact is rated High by NVD (CVSS), though the primary real-world consequence is availability loss; there is no evidence of direct data exfiltration via this vector (pkg.go.dev, EUVD).
착취 단계
- Reconnaissance: Identify services built with Go that use
golang.org/x/crypto/sshversions prior to 0.52.0 — this includes SSH servers, clients, or any application embedding Go SSH functionality (e.g., Portainer, rclone, Pulumi Kubernetes provider). - Establish SSH connection: Initiate a standard SSH connection to the target service. No credentials are required to begin the protocol handshake.
- Send unsolicited global request responses: During or after the SSH handshake, send a high volume of SSH
SSH_MSG_REQUEST_SUCCESSorSSH_MSG_REQUEST_FAILUREmessages (global request responses) that were never requested by the server. - Fill internal buffer: The target's read loop goroutine attempts to queue these responses into an internal channel buffer. Once the buffer is full, the goroutine blocks indefinitely.
- Trigger resource leak: Repeat across multiple connections. Each blocked goroutine cannot be freed by
Close(), causing cumulative goroutine and memory leaks that degrade or crash the target service (Go Issue, pkg.go.dev).
타협의 징후
- Network: Unusual volume of SSH connections from a single source IP that do not complete normal authentication flows; connections that remain open indefinitely without activity.
- Process/Runtime: Rapidly increasing goroutine count in Go application metrics (e.g.,
runtime.NumGoroutine()growing unboundedly); elevated memory consumption in SSH-serving Go processes. - Logs: SSH connection log entries showing connections established but never cleanly terminated; absence of normal disconnect or timeout log entries for established sessions.
- System: Increasing file descriptor usage associated with the Go SSH process; system-level OOM (out-of-memory) events or process crashes in applications using
golang.org/x/crypto/ssh(Go Issue, oss-sec).
완화 및 해결 방법
The primary remediation is to update golang.org/x/crypto to version 0.52.0 or later, which discards unsolicited global SSH responses instead of queuing them. Applications and distributions that bundle this package — including rclone, Portainer, Pulumi Kubernetes provider, and others — should update to their respective patched releases. As a network-level workaround, restrict SSH access to trusted peers only using firewall rules or network segmentation to reduce exposure until patching is complete (pkg.go.dev, Go CL 781640, Go CL 781664).
커뮤니티 반응
The Go security team disclosed the vulnerability via the golang-announce mailing list and published a Go vulnerability database entry (GO-2026-5017). The issue was also discussed on the oss-security mailing list. Multiple Linux distributions including openSUSE and Amazon Linux 2/2023 issued security advisories and package updates. Downstream projects such as rclone, Portainer, and Pulumi Kubernetes provider have released patched versions incorporating the fix (golang-announce, oss-sec, rclone changelog, Portainer release).
추가 자료
- pkg.go.dev — Go Vulnerability Database entry GO-2026-5017
- Go Issue — Official Go issue tracker report
- golang-announce — Go security announcement mailing list
- Go CL 781640 — Primary patch code review
- oss-sec — oss-security mailing list disclosure
- Amazon Linux Advisory — Amazon Linux 2023 security advisory
- openSUSE Advisory — openSUSE security announcement
근원: 이 보고서는 AI를 사용하여 생성되었습니다.
관련 cAdvisor 취약점:
무료 취약성 평가
클라우드 보안 태세를 벤치마킹합니다
9개의 보안 도메인에서 클라우드 보안 관행을 평가하여 위험 수준을 벤치마킹하고 방어의 허점을 식별합니다.
추가 Wiz 리소스
맞춤형 데모 받기
맞춤형 데모 신청하기
"내가 본 최고의 사용자 경험은 클라우드 워크로드에 대한 완전한 가시성을 제공합니다."
"Wiz는 클라우드 환경에서 무슨 일이 일어나고 있는지 볼 수 있는 단일 창을 제공합니다."
"우리는 Wiz가 무언가를 중요한 것으로 식별하면 실제로 중요하다는 것을 알고 있습니다."