HomeDefault status
unaffected
Any version before 0.52.0
affected
Description
SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil.
Problem types
CWE-476: NULL Pointer Dereference
Product status
Any version before 0.52.0
Credits
NCC Group Cryptography Services, sponsored by Teleport
References
groups.google.com/g/golang-announce/c/a082jnz-LvI