CVE-2026-56854
Published: August 30, 2026Last modified: September 3, 2026
Description
The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions returned by the PasswordCallback, KeyboardInteractiveCallback, NoClientAuthCallback, and GSSAPIWithMICConfig.AllowLogin callbacks were not validated against the client's remote address, so a source-address restriction set by those callbacks was silently ignored. The check is now applied to the Permissions returned by any authentication callback.
Severity score breakdown
| Parameter | Value |
|---|---|
| Base score | 7.5 |
| Attack Vector | NETWORK |
| Attack complexity | LOW |
| Privileges required | NONE |
| User interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality | HIGH |
| Integrity impact | NONE |
| Availability impact | NONE |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Status
| Product | Release | Package | Status |
|---|---|---|---|
| Alpaquita Linux | 23 LTS | buildah | Vulnerable (1.28.0-r1) |
| containerd | Vulnerable (1.6.10-r0) | ||
| podman | Vulnerable (4.3.1-r0) | ||
| skopeo | Vulnerable (1.10.0-r2) | ||
| 25 LTS | buildah | Vulnerable (1.40.0-r0) | |
| calicoctl | Vulnerable (3.31.3-r0) | ||
| cilium-cli | Vulnerable (0.19.0-r12) | ||
| containerd | Vulnerable (2.1.1-r0) | ||
| docker | Vulnerable (28.2.1-r0) | ||
| docker-cli-buildx | Vulnerable (0.24.0-r0) | ||
| etcd | Vulnerable (3.6.4-r6) | ||
| google-guest-agent | Vulnerable (20250521.00-r0) | ||
| helm | Vulnerable (3.19.0-r4) | ||
| kubernetes | Vulnerable (1.35.0-r1) | ||
| osv-scanner | Vulnerable (2.1.0-r4) | ||
| podman | Vulnerable (5.5.0-r0) | ||
| rootlesskit | Vulnerable (2.3.5-r0) | ||
| skopeo | Vulnerable (1.18.0-r2) | ||
| Stream | buildah | Vulnerable (1.31.0-r0) | |
| calicoctl | Vulnerable (3.31.3-r0) | ||
| cilium-cli | Vulnerable (0.19.0-r12) | ||
| containerd | Vulnerable (1.7.2-r1) | ||
| docker | Vulnerable (24.0.2-r0) | ||
| docker-cli-buildx | Vulnerable (0.11.0-r0) | ||
| etcd | Vulnerable (3.6.4-r6) | ||
| google-guest-agent | Vulnerable (20250214.01-r0) | ||
| grype | Vulnerable (0.100.0-r0) | ||
| helm | Vulnerable (3.19.0-r4) | ||
| kubernetes | Vulnerable (1.35.0-r1) | ||
| osv-scanner | Vulnerable (2.1.0-r2) | ||
| podman | Vulnerable (4.5.1-r1) | ||
| rootlesskit | Vulnerable (2.1.0-r0) | ||
| skopeo | Vulnerable (1.13.0-r1) |