Skip to content

x/crypto/ssh/knownhosts: failure to enforce @revoked status #79568

@thatnealpatel

Description

@thatnealpatel

Previously, a revoked SignatureKey belonging to a CA
was not correctly checked for revocation. Now, both the
key and key.SignatureKey are checked for @Revoked.

This is CVE-2026-42508 and Go issue https://go.dev/issue/79568.


This was a PUBLIC track issue, tracked in http://b/502121237.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions