- Description
- SSH Agent servers do not validate the size of messages when processing new identity requests, which may cause the program to panic if the message is malformed due to an out of bounds read.
- Source
- security@golang.org
- NVD status
- Analyzed
- Products
- crypto
CVSS 3.1
- Type
- Secondary
- Base score
- 5.3
- Impact score
- 1.4
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- Severity
- MEDIUM
- 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CWE-125
- Hype score
- Not currently trending
SUSE released fixes for kubevirt 1.6 and 1.7 addressing CVE-2025-47911, CVE-2025-47913 and CVE-2025-47914 privilege escalation and denial-of-service bugs in embedded Go components, Linuxsecurity reported. https://t.co/6QY6iezav6
@threatcluster
16 Jun 2026
55 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Critical Podman security patch: CVE-2025-47914 (moderate severity) affects ssh-agent in #SUSE distributions. Read more: 👉 https://t.co/LFlrCNDyjO #Security https://t.co/xUJ6RwPb8d
@Cezar_H_Linux
15 Jan 2026
54 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
🚨 Security Update: CVE-2025-47914 affects Podman on #openSUSE Leap 15.4 & SUSE Linux Enterprise Micro. CVSS:4.0 score: 6.9. Patch now to prevent SSH-agent panic from out-of-bounds read. Read more: 👉 https://t.co/Um8JgbcTsb #Security https://t.co/lvtK72LLBQ
@Cezar_H_Linux
15 Jan 2026
59 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Just 24hrs after CVE-2025-47913, CVE-2025-47914 and CVE-2025-58181 hit the @golang ecosystem, the team has remediated the CVEs across the entire @Docker Hardened Images catalog. It is nice to be fast but more importantly, this means security for our customers.
@cdupuis
21 Nov 2025
70 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:golang:crypto:*:*:*:*:*:go:*:*",
"matchCriteriaId": "0DB7D01D-5361-40FC-83A9-91A601A0321D",
"versionEndExcluding": "0.45.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]