← All Advisories

SSH Channel Write Path Overflows a Size Counter on Payloads Larger Than 4GB, Causing the Write Loop to Spin Indefinitely Sending Empty Packets Without Making Progress

Last refreshed2026-09-28

Status: UPDATED  |  Advisory ID: CVE-2026-39834

Key Details

CVECVE-2026-39834
CVSS Score / Version9.1 (Critical) / CVSS v3.1
Updated2026-07-23
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is high; availability impact is high.
Affected productsgolang crypto
Classified asCWE-190 (Integer Overflow or Wraparound)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
golangcrypto
SubsystemsGeneral OT
SectorsMultiple

What to Know

When writing data larger than 4GB in a single Write call on an SSH channel, an integer overflow in the internal payload size calculation caused the write loop to spin indefinitely, sending empty packets without making progress. The size comparison now uses int64 to prevent truncation. (NVD)

What to Do

Monitor golang's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-39834
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-39834
Vendor advisoryhttps://pkg.go.dev/vuln/GO-2026-5020