Overview
A flaw in golang.org/x/crypto/ssh/agent causes the SSH agent client to panic when a peer responds with the generic SSH_AGENT_SUCCESS (0x06) message to requests expecting typed replies (e.g., List, Sign). The unmarshal layer produces an unexpected message type, which the client code does not handle, leading to panic("unreachable") or a nil-pointer dereference. A malicious agent or forwarded connection can exploit this to terminate the client process.
Vendor advisories
- RHSA-2026:2769 · Red Hat · fixed in: Red Hat Ceph Storage 7.1 Tools · released 2026-02-17 · advisory
- RHSA-2026:14868 · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0) · released 2026-05-07 · advisory
- RHSA-2026:5167 · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0), Red Hat Enterprise Linux CodeReady Linux Builder EUS (v. 10.0) · released 2026-03-19 · advisory
- RHSA-2026:0436 · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-01-12 · advisory
- RHSA-2026:0545 · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux CodeReady Linux Builder (v. 10) · released 2026-01-14 · advisory
- RHSA-2026:0753 · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2026-01-19 · advisory
- RHSA-2026:10703 · Red Hat · fixed in: Red Hat Enterprise Linux AppStream AUS (v.8.6), Red Hat Enterprise Linux AppStream E4S (v.8.6), Red Hat Enterprise Linux AppStream TUS (v.8.6) · released 2026-04-27 · advisory
- RHSA-2026:19634 · Red Hat · fixed in: Red Hat Enterprise Linux AppStream AUS (v.8.6), Red Hat Enterprise Linux AppStream E4S (v.8.6), Red Hat Enterprise Linux AppStream TUS (v.8.6) · released 2026-05-20 · advisory
- RHSA-2026:4693 · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.8.8), Red Hat Enterprise Linux AppStream TUS (v.8.8) · released 2026-03-17 · advisory
- RHSA-2026:16701 · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.8.8), Red Hat Enterprise Linux AppStream TUS (v.8.8) · released 2026-05-13 · advisory
- RHSA-2026:16102 · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.0) · released 2026-05-11 · advisory
- Red Hat VEX · Important · affected: Multicluster Engine for Kubernetes, OpenShift Developer Tools and Services, OpenShift Serverless, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Ansible Automation Platform 2, Red Hat Ceph Storage 6, … · no fix planned: Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Edge Manager preview, Red Hat Enterprise Linux AI (RHEL AI), Red Hat OpenShift Container Platform 4, … · updated 2026-09-21 · vex
golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS — rated Important by Red Hat. Released 2025-11-13, updated 2026-09-21.
Affected:
- Multicluster Engine for Kubernetes
- OpenShift Developer Tools and Services
- OpenShift Serverless
- Red Hat Advanced Cluster Management for Kubernetes 2
- Red Hat Ansible Automation Platform 2
- Red Hat Ceph Storage 6
- Red Hat Edge Manager preview
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux AI (RHEL AI)
- Red Hat OpenShift Container Platform 4
- Red Hat OpenShift GitOps
- Red Hat OpenShift Virtualization 4
- Red Hat OpenStack Platform 16.2
Fixed:
- Red Hat Ceph Storage 7.1 Tools
- Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- Red Hat Enterprise Linux AppStream (v. 10)
- Red Hat Enterprise Linux AppStream (v. 8)
- Red Hat Enterprise Linux AppStream AUS (v.8.6)
- Red Hat Enterprise Linux AppStream E4S (v.8.6)
- Red Hat Enterprise Linux AppStream TUS (v.8.6)
- Red Hat Enterprise Linux AppStream E4S (v.8.8)
- Red Hat Enterprise Linux AppStream TUS (v.8.8)
- Red Hat Enterprise Linux AppStream E4S (v.9.0)
- Red Hat Enterprise Linux AppStream E4S (v.9.2)
- Red Hat Enterprise Linux AppStream EUS (v.9.4)
- Red Hat Enterprise Linux AppStream EUS (v.9.6)
- Red Hat Enterprise Linux AppStream (v. 9)
- Builds for Red Hat OpenShift 1.6.0
- Red Hat Enterprise Linux CodeReady Linux Builder EUS (v. 10.0)
- Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
- DevWorkspace Operator 0.39
- OpenShift API for Data Protection 1.6
- Red Hat Advanced Cluster Management for Kubernetes 2.15
- Red Hat Ceph Storage 7.1
- Red Hat Ceph Storage 8
- Red Hat Ceph Storage 9.0
- Red Hat Container Native Virtualization 4.14
- Red Hat Container Native Virtualization 4.16
- Red Hat Container Native Virtualization 4.19
- Red Hat Container Native Virtualization 4.20
- Red Hat OpenShift AI 2.25
- Red Hat OpenShift GitOps 1.17
- Red Hat OpenShift GitOps 1.18
- Red Hat OpenShift Pipelines 1.2
- Red Hat OpenStack Platform 16.2
- Red Hat OpenStack Platform 17.1
- Red Hat Openshift Data Foundation 4.20
- Red Hat Quay 3.10
- Red Hat Quay 3.12
- Red Hat Quay 3.13
- Red Hat Quay 3.14
- Red Hat Quay 3.15
- Red Hat Quay 3.16
No fix planned:
- Red Hat Advanced Cluster Management for Kubernetes 2
- Red Hat Edge Manager preview
- Red Hat Enterprise Linux AI (RHEL AI)
- Red Hat OpenShift Container Platform 4
- Red Hat OpenShift GitOps
- Red Hat OpenShift Virtualization 4
- Red Hat OpenStack Platform 16.2
- Multicluster Engine for Kubernetes
- OpenShift Developer Tools and Services
- OpenShift Serverless
- Red Hat Ansible Automation Platform 2
- Red Hat Ceph Storage 6
- Red Hat Enterprise Linux 8
Not affected:
- Red Hat Enterprise Linux AppStream E4S (v.9.0)
- Builds for Red Hat OpenShift 1.6.0
- DevWorkspace Operator 0.39
- OpenShift API for Data Protection 1.6
- Red Hat Advanced Cluster Management for Kubernetes 2.15
- Red Hat Ceph Storage 7.1
- Red Hat Ceph Storage 8
- Red Hat Ceph Storage 9.0
- Red Hat Container Native Virtualization 4.14
- Red Hat Container Native Virtualization 4.16
Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258
For supported configurations, refer to:
https://access.redhat.com/articles/1548993 https://access.redhat.com/errata/RHSA-2026:2769
For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:14868
For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:5167
Workarounds / mitigations:
- No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability.
Package advisory (CVE-2025-47913)
Affected packages:
golang.org/x/crypto/ssh/agent < 0.43.0
Patched in:
golang.org/x/crypto/ssh/agent 0.43.0
Source: https://osv.dev/vulnerability/GHSA-56w8-48fp-6mgv