CVE-2026-42508
golang.org/x/crypto golang.org/x/crypto/ssh/knownhosts, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8 취약점
Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.
- 대응 우선순위
- 점검
- CVSS
- 9.1
- EPSS
- 0.57% 백분위 43.9% · 2026.08.04 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.05.22