ssh: drop traffic on undecided channels A channel in the mux's chanList is not usable until it is established: an outbound channel has no confirmed remote id until the peer's open confirmation, and an inbound channel is not serviced by the application until it is accepted. handlePacket processed any channel message on it, so a misbehaving peer could flood channel requests and block the mux read loop on the send to incomingRequests, deadlocking the connection, or close an outbound channel before confirming it, making the victim tear down a half-initialized channel and emit a close for remote id 0, an unrelated channel of the peer. No such packet can be legitimate: the peer learns an inbound channel's local id only from the confirmation we have not sent yet, and on an outbound channel RFC 4254 lets it answer the open request only with a confirmation or a failure. Add an established flag, set when the channel becomes usable: for an outbound channel when the open response is received, for an inbound channel by Accept before the confirmation is sent. Until then handlePacket drops every packet other than the open response. The flag is separate from decided, which Reject also sets: a rejected channel is decided but must never carry traffic. Fixes CVE-2026-78662 Fixes golang/go#81316 Change-Id: Ib0983bb216a49808a2db1f4a4d92ee9fe38a3c51 Reviewed-on: https://go-review.googlesource.com/c/crypto/+/826504 Auto-Submit: Gopher Robot <gobot@golang.org> LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com <golang-scoped@luci-project-accounts.iam.gserviceaccount.com> Reviewed-by: Roland Shoemaker <roland@golang.org> Reviewed-by: Neal Patel <nealpatel@google.com> Reviewed-by: Nicholas Husin <husin@google.com>
This repository holds supplementary Go cryptography packages.
This repository uses Gerrit for code changes. To learn how to submit changes to this repository, see https://go.dev/doc/contribute.
The git repository is https://go.googlesource.com/crypto.
The main issue tracker for the crypto repository is located at https://go.dev/issues. Prefix your issue with “x/crypto:” in the subject line, so it is easy to find.
Note that contributions to the cryptography package receive additional scrutiny due to their sensitive nature. Patches may take longer than normal to receive feedback.