{"id":"CVE-2025-47913","title":"golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS (CVE-2025-47913)","summary":"A flaw in golang.org/x/crypto/ssh/agent causes the SSH agent client to panic when a peer responds with the generic SSH_AGENT_SUCCESS (0x06) message to requests expecting typed replies (e.g., List, Sign). The unmarshal layer produces an une…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-241","vendor":"Red Hat","product":"Red Hat Enterprise Linux AppStream E4S (v.8.6)","affected":["multicluster_engine_for_kubernetes","openshift_developer_tools_and_services","openshift_serverless","advanced_cluster_management_for_kubernetes 2","ansible_automation_platform 2","ceph_storage 6","edge_manager_preview","enterprise_linux 8","enterprise_linux_ai_rhel_ai","openshift_container_platform 4","openshift_gitops","openshift_virtualization 4","openstack_platform 16.2","ceph_storage_7_1_tools","enterprise_linux_appstream_eus_v_10_0","enterprise_linux_appstream_v_10","enterprise_linux_appstream_v_8","enterprise_linux_appstream_aus_v_8_6","enterprise_linux_appstream_e4s_v_8_6","enterprise_linux_appstream_tus_v_8_6","enterprise_linux_appstream_e4s_v_8_8","enterprise_linux_appstream_tus_v_8_8","enterprise_linux_appstream_e4s_v_9_0","enterprise_linux_appstream_e4s_v_9_2","enterprise_linux_appstream_eus_v_9_4","enterprise_linux_appstream_eus_v_9_6","enterprise_linux_appstream_v_9","builds_for_red_hat_openshift 1.6.0","enterprise_linux_codeready_linux_builder_eus_v_10_0","enterprise_linux_codeready_linux_builder_v_10","devworkspace_operator 0.39","openshift_api_for_data_protection 1.6","advanced_cluster_management_for_kubernetes 2.15","ceph_storage 7.1","ceph_storage 8","ceph_storage 9.0","container_native_virtualization 4.14","container_native_virtualization 4.16","container_native_virtualization 4.19","container_native_virtualization 4.20"],"patched":["ceph_storage_7_1_tools","enterprise_linux_appstream_eus_v_10_0","enterprise_linux_appstream_v_10","enterprise_linux_appstream_v_8","enterprise_linux_appstream_aus_v_8_6","enterprise_linux_appstream_e4s_v_8_6","enterprise_linux_appstream_tus_v_8_6","enterprise_linux_appstream_e4s_v_8_8","enterprise_linux_appstream_tus_v_8_8","enterprise_linux_appstream_e4s_v_9_0","enterprise_linux_appstream_e4s_v_9_2","enterprise_linux_appstream_eus_v_9_4","enterprise_linux_appstream_eus_v_9_6","enterprise_linux_appstream_v_9","builds_for_red_hat_openshift 1.6.0","enterprise_linux_codeready_linux_builder_eus_v_10_0","enterprise_linux_codeready_linux_builder_v_10","devworkspace_operator 0.39","openshift_api_for_data_protection 1.6","advanced_cluster_management_for_kubernetes 2.15","ceph_storage 7.1","ceph_storage 8","ceph_storage 9.0","container_native_virtualization 4.14","container_native_virtualization 4.16","container_native_virtualization 4.19","container_native_virtualization 4.20","openshift_ai 2.25","openshift_gitops 1.17","openshift_gitops 1.18","openshift_pipelines 1.2","openstack_platform 16.2","openstack_platform 17.1","openshift_data_foundation 4.20","quay 3.10","quay 3.12","quay 3.13","quay 3.14","quay 3.15","quay 3.16"],"published":"2025-11-13","updated":"2026-09-21","sourceUpdated":"2026-09-21T22:09:38+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-47913.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-47913.json"},{"url":"https://access.redhat.com/security/cve/CVE-2025-47913"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2414943"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-47913"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-47913"},{"url":"https://github.com/advisories/GHSA-hcg3-q754-cr77"},{"url":"https://go.dev/cl/700295"},{"url":"https://go.dev/issue/75178"},{"url":"https://pkg.go.dev/vuln/GO-2025-4116"},{"url":"https://access.redhat.com/errata/RHSA-2026:2769"},{"url":"https://access.redhat.com/errata/RHSA-2026:14868"},{"url":"https://access.redhat.com/errata/RHSA-2026:5167"},{"url":"https://access.redhat.com/errata/RHSA-2026:0436"},{"url":"https://access.redhat.com/errata/RHSA-2026:0545"},{"url":"https://access.redhat.com/errata/RHSA-2026:0753"},{"url":"https://access.redhat.com/errata/RHSA-2026:10703"},{"url":"https://access.redhat.com/errata/RHSA-2026:19634"},{"url":"https://access.redhat.com/errata/RHSA-2026:4693"},{"url":"https://access.redhat.com/errata/RHSA-2026:16701"},{"url":"https://access.redhat.com/errata/RHSA-2026:16102"},{"url":"https://access.redhat.com/errata/RHSA-2026:8325"},{"url":"https://access.redhat.com/errata/RHSA-2026:4532"},{"url":"https://access.redhat.com/errata/RHSA-2026:16702"},{"url":"https://access.redhat.com/errata/RHSA-2026:12030"},{"url":"https://access.redhat.com/errata/RHSA-2026:5222"},{"url":"https://access.redhat.com/errata/RHSA-2026:11749"},{"url":"https://access.redhat.com/errata/RHSA-2026:1084"},{"url":"https://access.redhat.com/errata/RHSA-2026:0437"},{"url":"https://access.redhat.com/errata/RHSA-2026:0470"},{"url":"https://access.redhat.com/errata/RHSA-2025:22743"},{"url":"https://github.com/golang/crypto"}],"tags":["csaf","vex","red-hat","osv","go"],"epss":0.00623,"epssPercentile":0.4854,"aliases":["GHSA-56w8-48fp-6mgv","GO-2025-4116"],"ecosystem":"go","ingestedAt":"2026-09-12T03:13:01.755Z","slug":"CVE-2025-47913","body":"## Overview\n\nA flaw in golang.org/x/crypto/ssh/agent causes the SSH agent client to panic when a peer responds with the generic SSH_AGENT_SUCCESS (0x06) message to requests expecting typed replies (e.g., List, Sign). The unmarshal layer produces an unexpected message type, which the client code does not handle, leading to panic(\"unreachable\") or a nil-pointer dereference. A malicious agent or forwarded connection can exploit this to terminate the client process.\n\n## Vendor advisories\n\n- **RHSA-2026:2769** · Red Hat · fixed in: Red Hat Ceph Storage 7.1 Tools · released 2026-02-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:2769)\n- **RHSA-2026:14868** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0) · released 2026-05-07 · [advisory](https://access.redhat.com/errata/RHSA-2026:14868)\n- **RHSA-2026:5167** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0), Red Hat Enterprise Linux CodeReady Linux Builder EUS (v. 10.0) · released 2026-03-19 · [advisory](https://access.redhat.com/errata/RHSA-2026:5167)\n- **RHSA-2026:0436** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-01-12 · [advisory](https://access.redhat.com/errata/RHSA-2026:0436)\n- **RHSA-2026:0545** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux CodeReady Linux Builder (v. 10) · released 2026-01-14 · [advisory](https://access.redhat.com/errata/RHSA-2026:0545)\n- **RHSA-2026:0753** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2026-01-19 · [advisory](https://access.redhat.com/errata/RHSA-2026:0753)\n- **RHSA-2026:10703** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream AUS (v.8.6), Red Hat Enterprise Linux AppStream E4S (v.8.6), Red Hat Enterprise Linux AppStream TUS (v.8.6) · released 2026-04-27 · [advisory](https://access.redhat.com/errata/RHSA-2026:10703)\n- **RHSA-2026:19634** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream AUS (v.8.6), Red Hat Enterprise Linux AppStream E4S (v.8.6), Red Hat Enterprise Linux AppStream TUS (v.8.6) · released 2026-05-20 · [advisory](https://access.redhat.com/errata/RHSA-2026:19634)\n- **RHSA-2026:4693** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.8.8), Red Hat Enterprise Linux AppStream TUS (v.8.8) · released 2026-03-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:4693)\n- **RHSA-2026:16701** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.8.8), Red Hat Enterprise Linux AppStream TUS (v.8.8) · released 2026-05-13 · [advisory](https://access.redhat.com/errata/RHSA-2026:16701)\n- **RHSA-2026:16102** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.0) · released 2026-05-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:16102)\n- **Red Hat VEX** · Important · affected: Multicluster Engine for Kubernetes, OpenShift Developer Tools and Services, OpenShift Serverless, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Ansible Automation Platform 2, Red Hat Ceph Storage 6, … · no fix planned: Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Edge Manager preview, Red Hat Enterprise Linux AI (RHEL AI), Red Hat OpenShift Container Platform 4, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-47913.json)\n\n**golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS** — rated Important by Red Hat. Released 2025-11-13, updated 2026-09-21.\n\nAffected:\n\n- Multicluster Engine for Kubernetes\n- OpenShift Developer Tools and Services\n- OpenShift Serverless\n- Red Hat Advanced Cluster Management for Kubernetes 2\n- Red Hat Ansible Automation Platform 2\n- Red Hat Ceph Storage 6\n- Red Hat Edge Manager preview\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux AI (RHEL AI)\n- Red Hat OpenShift Container Platform 4\n- Red Hat OpenShift GitOps\n- Red Hat OpenShift Virtualization 4\n- Red Hat OpenStack Platform 16.2\n\nFixed:\n\n- Red Hat Ceph Storage 7.1 Tools\n- Red Hat Enterprise Linux AppStream EUS (v. 10.0)\n- Red Hat Enterprise Linux AppStream (v. 10)\n- Red Hat Enterprise Linux AppStream (v. 8)\n- Red Hat Enterprise Linux AppStream AUS (v.8.6)\n- Red Hat Enterprise Linux AppStream E4S (v.8.6)\n- Red Hat Enterprise Linux AppStream TUS (v.8.6)\n- Red Hat Enterprise Linux AppStream E4S (v.8.8)\n- Red Hat Enterprise Linux AppStream TUS (v.8.8)\n- Red Hat Enterprise Linux AppStream E4S (v.9.0)\n- Red Hat Enterprise Linux AppStream E4S (v.9.2)\n- Red Hat Enterprise Linux AppStream EUS (v.9.4)\n- Red Hat Enterprise Linux AppStream EUS (v.9.6)\n- Red Hat Enterprise Linux AppStream (v. 9)\n- Builds for Red Hat OpenShift 1.6.0\n- Red Hat Enterprise Linux CodeReady Linux Builder EUS (v. 10.0)\n- Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)\n- DevWorkspace Operator 0.39\n- OpenShift API for Data Protection 1.6\n- Red Hat Advanced Cluster Management for Kubernetes 2.15\n- Red Hat Ceph Storage 7.1\n- Red Hat Ceph Storage 8\n- Red Hat Ceph Storage 9.0\n- Red Hat Container Native Virtualization 4.14\n- Red Hat Container Native Virtualization 4.16\n- Red Hat Container Native Virtualization 4.19\n- Red Hat Container Native Virtualization 4.20\n- Red Hat OpenShift AI 2.25\n- Red Hat OpenShift GitOps 1.17\n- Red Hat OpenShift GitOps 1.18\n- Red Hat OpenShift Pipelines 1.2\n- Red Hat OpenStack Platform 16.2\n- Red Hat OpenStack Platform 17.1\n- Red Hat Openshift Data Foundation 4.20\n- Red Hat Quay 3.10\n- Red Hat Quay 3.12\n- Red Hat Quay 3.13\n- Red Hat Quay 3.14\n- Red Hat Quay 3.15\n- Red Hat Quay 3.16\n\nNo fix planned:\n\n- Red Hat Advanced Cluster Management for Kubernetes 2\n- Red Hat Edge Manager preview\n- Red Hat Enterprise Linux AI (RHEL AI)\n- Red Hat OpenShift Container Platform 4\n- Red Hat OpenShift GitOps\n- Red Hat OpenShift Virtualization 4\n- Red Hat OpenStack Platform 16.2\n- Multicluster Engine for Kubernetes\n- OpenShift Developer Tools and Services\n- OpenShift Serverless\n- Red Hat Ansible Automation Platform 2\n- Red Hat Ceph Storage 6\n- Red Hat Enterprise Linux 8\n\nNot affected:\n\n- Red Hat Enterprise Linux AppStream E4S (v.9.0)\n- Builds for Red Hat OpenShift 1.6.0\n- DevWorkspace Operator 0.39\n- OpenShift API for Data Protection 1.6\n- Red Hat Advanced Cluster Management for Kubernetes 2.15\n- Red Hat Ceph Storage 7.1\n- Red Hat Ceph Storage 8\n- Red Hat Ceph Storage 9.0\n- Red Hat Container Native Virtualization 4.14\n- Red Hat Container Native Virtualization 4.16\n\n## Remediation\n\nBefore applying this update, make sure all previously released errata relevant to your system have been applied.\n\nFor details on how to apply this update, refer to:\n\nhttps://access.redhat.com/articles/11258\n\nFor supported configurations, refer to:\n\nhttps://access.redhat.com/articles/1548993 https://access.redhat.com/errata/RHSA-2026:2769\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:14868\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:5167\n\nWorkarounds / mitigations:\n\n- No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability.\n\n## Package advisory (CVE-2025-47913)\n\nAffected packages:\n\n- `golang.org/x/crypto/ssh/agent < 0.43.0`\n\nPatched in:\n\n- `golang.org/x/crypto/ssh/agent 0.43.0`\n\nSource: https://osv.dev/vulnerability/GHSA-56w8-48fp-6mgv","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}