When adding a key to a remote agent constraint extensions such as [email protected] were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. Additionally, the in-memory keyring returned by NewKeyring() now rejects keys with unsupported constraint extensions instead of silently ignoring them.
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39832.json
https://pkg.go.dev/vuln/GO-2026-5006
https://groups.google.com/g/golang-announce/c/a082jnz-LvI
https://bugzilla.redhat.com/show_bug.cgi?id=2480685
https://access.redhat.com/security/cve/CVE-2026-39832
https://access.redhat.com/errata/RHSA-2026:43692
https://access.redhat.com/errata/RHSA-2026:43052
https://access.redhat.com/errata/RHSA-2026:42796
https://access.redhat.com/errata/RHSA-2026:42146
https://access.redhat.com/errata/RHSA-2026:41066
https://access.redhat.com/errata/RHSA-2026:41036
https://access.redhat.com/errata/RHSA-2026:41031
https://access.redhat.com/errata/RHSA-2026:41019
https://access.redhat.com/errata/RHSA-2026:40972
https://access.redhat.com/errata/RHSA-2026:40945
https://access.redhat.com/errata/RHSA-2026:40262
https://access.redhat.com/errata/RHSA-2026:40118
https://access.redhat.com/errata/RHSA-2026:37410
https://access.redhat.com/errata/RHSA-2026:37387
https://access.redhat.com/errata/RHSA-2026:37271
https://access.redhat.com/errata/RHSA-2026:37123
https://access.redhat.com/errata/RHSA-2026:37072
https://access.redhat.com/errata/RHSA-2026:36797
https://access.redhat.com/errata/RHSA-2026:36796
https://access.redhat.com/errata/RHSA-2026:36651
https://access.redhat.com/errata/RHSA-2026:36648
https://access.redhat.com/errata/RHSA-2026:36625
https://access.redhat.com/errata/RHSA-2026:36319