CVE-2026-56855
Docker 취약성 분석 및 완화

개요

CVE-2026-56855 is a denial-of-service vulnerability in the golang.org/x/crypto/ssh package that allows a malicious SSH peer to deadlock an entire connection by sending crafted channel messages. After a channel is established, the affected implementation would buffer and block on unhandled RFC 4254 messages rather than treating them as protocol errors, enabling a remote attacker to freeze the connection. All versions of golang.org/x/crypto/ssh prior to 0.56.0 are affected. It carries a CVSS v3.1 base score of 7.5 (High) (Feedly, OSV).

기술적 세부 사항

The root cause is classified as CWE-770 (Allocation of Resources Without Limits or Throttling). When an SSH channel was established, the library did not fully handle all RFC 4254 channel message types — global requests were not explicitly processed, and unrecognized messages were silently buffered rather than rejected. A malicious peer could exploit this by sending crafted, unexpected channel messages that caused the connection goroutine to block indefinitely, deadlocking the entire SSH connection. The fix ensures all RFC 4254 channel messages are handled, global requests are processed explicitly, and any remaining unrecognized messages trigger a protocol error that tears down the connection (OSV, Go Issue, Go CL).

영향

Successful exploitation results in a complete denial of service for the affected SSH connection, with high availability impact and no confidentiality or integrity impact. An unauthenticated remote attacker can deadlock any SSH connection handled by the vulnerable library, potentially rendering SSH-dependent services unresponsive. Applications and services built on golang.org/x/crypto/ssh — including custom SSH servers and clients — are at risk of connection-level resource exhaustion (Feedly, OSV).

악용 가능성

No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the disclosure date. The NVD SSVC assessment indicates no known exploitation and classifies the vulnerability as automatable with partial technical impact. The EPSS score is approximately 0.0017 (0.17%), reflecting a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Feedly, OSV).

착취 단계

  1. Identify target: Locate services or applications using golang.org/x/crypto/ssh versions prior to 0.56.0 as an SSH server or client (e.g., custom Go-based SSH servers).
  2. Establish SSH channel: Complete the SSH handshake and open a channel with the target service to reach the vulnerable post-channel-establishment state.
  3. Send crafted messages: Transmit RFC 4254 channel messages of types not explicitly handled by the library (e.g., unrecognized global request types or unexpected channel message types).
  4. Trigger deadlock: The server's connection goroutine attempts to buffer the unhandled messages and blocks indefinitely, deadlocking the entire SSH connection and making the service unresponsive to further requests (OSV, Go Issue).

타협의 징후

  • Network: Persistent, long-lived SSH connections from unexpected or unknown source IPs that do not complete normal session activity.
  • Process: Go application processes with SSH connection goroutines stuck in a blocked/waiting state; elevated goroutine counts in Go runtime metrics.
  • Logs: SSH connection logs showing sessions that opened channels but never completed or terminated normally; absence of session close events following channel open events.
  • Availability: Sudden unresponsiveness of SSH-based Go services without corresponding crash logs or OS-level errors.

완화 및 해결 방법

Upgrade golang.org/x/crypto to version 0.56.0 or later, which includes the fix that properly handles all RFC 4254 channel messages and tears down connections on protocol errors instead of blocking. Developers should update their go.mod dependencies and rebuild affected applications. No configuration-based workaround is available; patching is the only remediation (OSV, Go CL, golang-announce).

커뮤니티 반응

The vulnerability was announced via the golang-announce mailing list and tracked in the Go vulnerability database. Community discussion has been limited, consistent with the moderate severity and narrow scope of the issue. No notable vendor statements or significant media coverage beyond standard vulnerability aggregator listings have been observed (golang-announce, OSV).

추가 자료

리눅스 배포판 수정 현황

주요 리눅스 배포판과 그 릴리스 전반에 걸친 가용성을 수정하세요.

Debian

수정됨

bookworm

golang-go.crypto

영향을 받은 사람들

sid

golang-go.crypto: 1:0.56.0-1

수정됨

trixie

golang-go.crypto

영향을 받은 사람들

Ubuntu

알 수 없음

bionic (esm-infra)

golang-defaults

알 수 없음

devel

golang-1.23

알 수 없음

focal (esm-apps)

golang-1.20

알 수 없음

focal (esm-infra)

golang-defaults

알 수 없음

jammy

golang-1.17

알 수 없음

jammy (esm-apps)

golang-1.20

알 수 없음

noble

golang-1.21

알 수 없음

noble (esm-apps)

golang-1.21

알 수 없음

RHEL / CentOS

영향을 받은 사람들

OpenShift

cri-o.src

영향을 받은 사람들

RHEL 8

container-tools:rhel8/buildah.src

영향을 받은 사람들

RHEL 9

buildah.src

영향을 받은 사람들

RHEL 10

buildah.src

영향을 받은 사람들

근원이 보고서는 AI를 사용하여 생성되었습니다.

관련 Docker 취약점:

CVE ID

심각도

점수

기술

구성 요소 이름

CISA KEV 익스플로잇

수정 사항이 있습니다.

게시된 날짜

CVE-2026-78662HIGH7.5
  • Docker logoDocker
  • headlamp-fips
아니요Sep 02, 2026
CVE-2026-56855HIGH7.5
  • Docker logoDocker
  • argo-workflows-3.7
아니요Sep 02, 2026
CVE-2026-75593HIGH7.2
  • Docker logoDocker
  • container-tools:rhel8::podman-gvproxy
아니요아니요Aug 19, 2026
CVE-2026-61711MEDIUM5.3
  • Docker logoDocker
  • docker-compose
아니요Aug 19, 2026
CVE-2026-61712LOW2.3
  • Docker logoDocker
  • conftest-fips
아니요Aug 19, 2026

무료 취약성 평가

클라우드 보안 태세를 벤치마킹합니다

9개의 보안 도메인에서 클라우드 보안 관행을 평가하여 위험 수준을 벤치마킹하고 방어의 허점을 식별합니다.

평가 요청

추가 Wiz 리소스

맞춤형 데모 받기

맞춤형 데모 신청하기

"내가 본 최고의 사용자 경험은 클라우드 워크로드에 대한 완전한 가시성을 제공합니다."
데이비드 에슬릭최고정보책임자(CISO)
"Wiz는 클라우드 환경에서 무슨 일이 일어나고 있는지 볼 수 있는 단일 창을 제공합니다."
아담 플레처최고 보안 책임자(CSO)
"우리는 Wiz가 무언가를 중요한 것으로 식별하면 실제로 중요하다는 것을 알고 있습니다."
그렉 포니아토프스키위협 및 취약성 관리 책임자