[ubuntu/questing-security] google-guest-agent 20250506.01-0ubuntu1.2 (Accepted)

Hlib Korzhynskyy hlib.korzhynskyy at canonical.com
Mon Jun 22 17:13:40 UTC 2026


google-guest-agent (20250506.01-0ubuntu1.2) questing-security; urgency=medium

  * SECURITY UPDATE: denial of service via unexpected SSH global responses
    - debian/extra/vendor/golang.org/x/crypto/ssh/mux.go: use a non-blocking
      send for global request responses and drain stale responses.
    - 4e7a7384ecbc8d519f6f4c11b36fa9d761fc8946
    - CVE-2026-39830
  * SECURITY UPDATE: user presence verification bypass for security keys
    - debian/extra/vendor/golang.org/x/crypto/ssh/keys.go: enforce the
      user-presence bit in signatures from FIDO/U2F security keys.
    - b61cf853a89d82cad68da5e12a6beca2116f8456
    - CVE-2026-39831
  * SECURITY UPDATE: denial of service via integer overflow on large writes
    - debian/extra/vendor/golang.org/x/crypto/ssh/channel.go: avoid uint32
      truncation that caused an infinite loop on large channel writes.
    - e052873987615dc96fe67607a9a6adb76311344f
    - CVE-2026-39834
  * SECURITY UPDATE: source-address critical option authorization bypass
    - debian/extra/vendor/golang.org/x/crypto/ssh/server.go: enforce the
      source-address critical option for all callback types.
    - 533fb3f7e4a5ae23f69d1837cd851d35ff5b76ce
    - CVE-2026-46595

Date: 2026-06-17 19:05:13.051362+00:00
Changed-By: Hlib Korzhynskyy <hlib.korzhynskyy at canonical.com>
https://launchpad.net/ubuntu/+source/google-guest-agent/20250506.01-0ubuntu1.2
-------------- next part --------------
Sorry, changesfile not available.


More information about the Questing-changes mailing list