[From nobody Wed Oct  7 00:37:10 2026
Received: (at submit) by bugs.debian.org; 1 Oct 2026 20:59:21 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
 (2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-4.9 required=4.0 tests=BAYES_00,FOURLA,
 FVGT_m_MULTI_ODD,MD5_SHA1_SUM,SPF_HELO_NONE,SPF_PASS autolearn=ham
 autolearn_force=no version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 144; hammy, 150; neutral, 228; spammy,
 0. spammytokens:
 hammytokens:0.000-+--UD:security-tracker.debian.org, 
 0.000-+--securitytrackerdebianorg,
 0.000-+--security-tracker.debian.org, 0.000-+--H*r:jmm,
 0.000-+--sk:teamse
Return-path: &lt;jmm@inutil.org&gt;
Received: from inutil.org ([51.38.114.215]:57562 helo=vps-b7ad3695.vps.ovh.net)
 by buxtehude.debian.org with esmtp (Exim 4.96)
 (envelope-from &lt;jmm@inutil.org&gt;) id 1xCNs8-0016o0-1R
 for submit@bugs.debian.org; Thu, 01 Oct 2026 20:59:21 +0000
Received: from soju.fritz.box (p548dc0ed.dip0.t-ipconnect.de [84.141.192.237])
 by vps-b7ad3695.vps.ovh.net (Postfix) with ESMTPSA id 2B307122
 for &lt;submit@bugs.debian.org&gt;; Thu,  1 Oct 2026 20:59:20 +0000 (UTC)
Received: from jmm by soju.fritz.box with local (Exim 4.100)
 (envelope-from &lt;jmm@soju.westfalen.local&gt;) id 1xCNs1-00000000kgC-3yUV
 for submit@bugs.debian.org; Thu, 01 Oct 2026 22:59:13 +0200
Date: Thu, 1 Oct 2026 22:59:13 +0200
To: submit@bugs.debian.org
Subject: rust-russh: CVE-2026-102820 CVE-2026-102821 CVE-2026-102822
 CVE-2026-102823 CVE-2026-102824 CVE-2026-102825
Message-ID: &lt;ar7JoX_ZTRRLTpPr@pisco.westfalen.local&gt;
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
From: =?UTF-8?Q?Moritz_M=C3=BChlenhoff?= &lt;jmm@inutil.org&gt;
Delivered-To: submit@bugs.debian.org

Source: rust-russh
X-Debbugs-CC: team@security.debian.org
Severity: grave
Tags: security

Hi,

The following vulnerabilities were published for rust-russh.

CVE-2026-102820[0]:
| pageant provides a [PageantStream] type that implements [AsyncRead]
| and [AsyncWrite] traits and can be used to talk to a running Pageant
| instance. Prior to pageant 0.2.3, the Windows pageant crate's
| pageant/src/wmmessage.rs MemoryMap::read function trusts a peer-
| controlled u32 response length supplied through the 8192-byte
| Pageant shared-memory mapping reached by
| AgentClient::connect_pageant. A local process that impersonates the
| Pageant window can make query_pageant_direct allocate up to
| approximately 4 GiB and copy beyond the mapped view, reliably
| crashing a russh client and conditionally exposing adjacent
| committed memory. This issue is fixed in pageant 0.2.3.

https://github.com/Eugeny/russh/security/advisories/GHSA-g4mp-vgx3-xrvm
Fixed by: https://github.com/Eugeny/russh/commit/5d566989ebabfdebfe6b33243d31765a0812260b (v0.63.2)


CVE-2026-102821[1]:
| Russh is a Rust SSH client and server library. Prior to 0.63.2, an
| authenticated remote peer can send SSH_MSG_KEXINIT without the
| required SSH_MSG_KEX_ECDH_INIT and then flood SSH_MSG_CHANNEL_OPEN
| messages while SessionKexState::InProgress prevents
| priority_receiver in russh/src/server/session.rs from being drained.
| The server continues processing network input and enqueues a
| ChannelOpenReply for each request on an unbounded channel, allowing
| one connection to grow memory until the process is terminated. This
| issue is fixed in version 0.63.2.

https://github.com/Eugeny/russh/security/advisories/GHSA-35g8-35p8-c8fw
Fixed by: https://github.com/Eugeny/russh/commit/a282af361ac99bc76b80876d1aae128e89dbf66b (v0.63.2)


CVE-2026-102822[2]:
| Russh is a Rust SSH client and server library. Prior to 0.63.1, a
| connection configured to permit mac=none can negotiate it with a
| MAC-requiring CTR or CBC block cipher because the selection logic
| validates needs_mac() only when MAC selection fails. A remote peer
| can then send a packet with a decrypted length of zero, causing
| russh/src/cipher/mod.rs to shrink the previously read block before
| indexing buffer.buffer[16..], which panics and terminates the
| connection task. This issue is fixed in version 0.63.1.

https://github.com/Eugeny/russh/security/advisories/GHSA-p8qx-h547-fjw9
Fixed by: https://github.com/Eugeny/russh/commit/2885385abfee279092a41d80c6cb6ac367353159 (v0.63.1)


CVE-2026-102823[3]:
| Russh is a Rust SSH client and server library. Prior to 0.63.1,
| client_read_authenticated in russh/src/client/encrypted.rs forwards
| CHANNEL_DATA, CHANNEL_EXTENDED_DATA, CHANNEL_EOF, CHANNEL_CLOSE,
| CHANNEL_OPEN_FAILURE, CHANNEL_SUCCESS, CHANNEL_FAILURE, and
| CHANNEL_REQUEST subtypes exit-status, exit-signal, and xon-xoff to
| public client::Handler callbacks without confirming that the
| ChannelId belongs to a channel the client opened and established. A
| malicious SSH server can send lifecycle events for predicted,
| unopened, unconfirmed, or released channel identifiers, causing
| application panics or corrupting command completion and exit-code
| tracking. This issue is fixed in version 0.63.1.

https://github.com/Eugeny/russh/security/advisories/GHSA-47hw-gvq5-r2gm
Fixed by: https://github.com/Eugeny/russh/commit/3430fd26ecafc0dc3705210f5f39a9119fa22774 (v0.63.1)


CVE-2026-102824[4]:
| Russh is a Rust SSH client and server library. Prior to 0.63.0, the
| hybrid ML-KEM 768 and X25519 implementation in
| russh/src/kex/hybrid_mlkem.rs accepts an all-zero 32-byte peer
| X25519 public key in both server_dh and compute_shared_secret,
| forcing the X25519 contribution to the combined shared secret to
| zero. A malicious SSH peer can therefore make the combined secret
| depend only on ML-KEM, defeating the hybrid exchange's intended
| fallback protection if ML-KEM is later weakened. This issue is fixed
| in version 0.63.0.

https://github.com/Eugeny/russh/security/advisories/GHSA-w3jg-pjxf-73p4
Fixed by: https://github.com/Eugeny/russh/commit/8da8967f196472576b1565d518a0ed60fce60f0c (v0.63.0)


CVE-2026-102825[5]:
| Russh is a Rust SSH client and server library. Prior to 0.62.6, the
| USERAUTH_REQUEST path reached from server::run_stream in
| russh/src/server/encrypted.rs increments self.common.auth_attempts
| but never compares it with server::Config.max_auth_attempts. An
| unauthenticated remote client can continue submitting authentication
| requests on one connection beyond the configured cap, bypassing the
| deployment's attempt-limiting policy and increasing online guessing
| opportunity and backend authentication workload. This issue is fixed
| in version 0.62.6.

https://github.com/Eugeny/russh/security/advisories/GHSA-g6xm-f9xp-qq35
Fixed by: https://github.com/Eugeny/russh/commit/f8fd0b11a393364dc7f01a182482d86adafdd653 (v0.62.6)


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities &amp; Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-102820
    https://www.cve.org/CVERecord?id=CVE-2026-102820
[1] https://security-tracker.debian.org/tracker/CVE-2026-102821
    https://www.cve.org/CVERecord?id=CVE-2026-102821
[2] https://security-tracker.debian.org/tracker/CVE-2026-102822
    https://www.cve.org/CVERecord?id=CVE-2026-102822
[3] https://security-tracker.debian.org/tracker/CVE-2026-102823
    https://www.cve.org/CVERecord?id=CVE-2026-102823
[4] https://security-tracker.debian.org/tracker/CVE-2026-102824
    https://www.cve.org/CVERecord?id=CVE-2026-102824
[5] https://security-tracker.debian.org/tracker/CVE-2026-102825
    https://www.cve.org/CVERecord?id=CVE-2026-102825

Please adjust the affected versions in the BTS as needed.
]