[Pkg-rust-maintainers] Bug#1149646: rust-russh: CVE-2026-102820 CVE-2026-102821 CVE-2026-102822 CVE-2026-102823 CVE-2026-102824 CVE-2026-102825
Moritz Mühlenhoff
jmm at inutil.org
Thu Oct 1 21:59:13 BST 2026
Source: rust-russh
X-Debbugs-CC: team at security.debian.org
Severity: grave
Tags: security
Hi,
The following vulnerabilities were published for rust-russh.
CVE-2026-102820[0]:
| pageant provides a [PageantStream] type that implements [AsyncRead]
| and [AsyncWrite] traits and can be used to talk to a running Pageant
| instance. Prior to pageant 0.2.3, the Windows pageant crate's
| pageant/src/wmmessage.rs MemoryMap::read function trusts a peer-
| controlled u32 response length supplied through the 8192-byte
| Pageant shared-memory mapping reached by
| AgentClient::connect_pageant. A local process that impersonates the
| Pageant window can make query_pageant_direct allocate up to
| approximately 4 GiB and copy beyond the mapped view, reliably
| crashing a russh client and conditionally exposing adjacent
| committed memory. This issue is fixed in pageant 0.2.3.
https://github.com/Eugeny/russh/security/advisories/GHSA-g4mp-vgx3-xrvm
Fixed by: https://github.com/Eugeny/russh/commit/5d566989ebabfdebfe6b33243d31765a0812260b (v0.63.2)
CVE-2026-102821[1]:
| Russh is a Rust SSH client and server library. Prior to 0.63.2, an
| authenticated remote peer can send SSH_MSG_KEXINIT without the
| required SSH_MSG_KEX_ECDH_INIT and then flood SSH_MSG_CHANNEL_OPEN
| messages while SessionKexState::InProgress prevents
| priority_receiver in russh/src/server/session.rs from being drained.
| The server continues processing network input and enqueues a
| ChannelOpenReply for each request on an unbounded channel, allowing
| one connection to grow memory until the process is terminated. This
| issue is fixed in version 0.63.2.
https://github.com/Eugeny/russh/security/advisories/GHSA-35g8-35p8-c8fw
Fixed by: https://github.com/Eugeny/russh/commit/a282af361ac99bc76b80876d1aae128e89dbf66b (v0.63.2)
CVE-2026-102822[2]:
| Russh is a Rust SSH client and server library. Prior to 0.63.1, a
| connection configured to permit mac=none can negotiate it with a
| MAC-requiring CTR or CBC block cipher because the selection logic
| validates needs_mac() only when MAC selection fails. A remote peer
| can then send a packet with a decrypted length of zero, causing
| russh/src/cipher/mod.rs to shrink the previously read block before
| indexing buffer.buffer[16..], which panics and terminates the
| connection task. This issue is fixed in version 0.63.1.
https://github.com/Eugeny/russh/security/advisories/GHSA-p8qx-h547-fjw9
Fixed by: https://github.com/Eugeny/russh/commit/2885385abfee279092a41d80c6cb6ac367353159 (v0.63.1)
CVE-2026-102823[3]:
| Russh is a Rust SSH client and server library. Prior to 0.63.1,
| client_read_authenticated in russh/src/client/encrypted.rs forwards
| CHANNEL_DATA, CHANNEL_EXTENDED_DATA, CHANNEL_EOF, CHANNEL_CLOSE,
| CHANNEL_OPEN_FAILURE, CHANNEL_SUCCESS, CHANNEL_FAILURE, and
| CHANNEL_REQUEST subtypes exit-status, exit-signal, and xon-xoff to
| public client::Handler callbacks without confirming that the
| ChannelId belongs to a channel the client opened and established. A
| malicious SSH server can send lifecycle events for predicted,
| unopened, unconfirmed, or released channel identifiers, causing
| application panics or corrupting command completion and exit-code
| tracking. This issue is fixed in version 0.63.1.
https://github.com/Eugeny/russh/security/advisories/GHSA-47hw-gvq5-r2gm
Fixed by: https://github.com/Eugeny/russh/commit/3430fd26ecafc0dc3705210f5f39a9119fa22774 (v0.63.1)
CVE-2026-102824[4]:
| Russh is a Rust SSH client and server library. Prior to 0.63.0, the
| hybrid ML-KEM 768 and X25519 implementation in
| russh/src/kex/hybrid_mlkem.rs accepts an all-zero 32-byte peer
| X25519 public key in both server_dh and compute_shared_secret,
| forcing the X25519 contribution to the combined shared secret to
| zero. A malicious SSH peer can therefore make the combined secret
| depend only on ML-KEM, defeating the hybrid exchange's intended
| fallback protection if ML-KEM is later weakened. This issue is fixed
| in version 0.63.0.
https://github.com/Eugeny/russh/security/advisories/GHSA-w3jg-pjxf-73p4
Fixed by: https://github.com/Eugeny/russh/commit/8da8967f196472576b1565d518a0ed60fce60f0c (v0.63.0)
CVE-2026-102825[5]:
| Russh is a Rust SSH client and server library. Prior to 0.62.6, the
| USERAUTH_REQUEST path reached from server::run_stream in
| russh/src/server/encrypted.rs increments self.common.auth_attempts
| but never compares it with server::Config.max_auth_attempts. An
| unauthenticated remote client can continue submitting authentication
| requests on one connection beyond the configured cap, bypassing the
| deployment's attempt-limiting policy and increasing online guessing
| opportunity and backend authentication workload. This issue is fixed
| in version 0.62.6.
https://github.com/Eugeny/russh/security/advisories/GHSA-g6xm-f9xp-qq35
Fixed by: https://github.com/Eugeny/russh/commit/f8fd0b11a393364dc7f01a182482d86adafdd653 (v0.62.6)
If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-102820
https://www.cve.org/CVERecord?id=CVE-2026-102820
[1] https://security-tracker.debian.org/tracker/CVE-2026-102821
https://www.cve.org/CVERecord?id=CVE-2026-102821
[2] https://security-tracker.debian.org/tracker/CVE-2026-102822
https://www.cve.org/CVERecord?id=CVE-2026-102822
[3] https://security-tracker.debian.org/tracker/CVE-2026-102823
https://www.cve.org/CVERecord?id=CVE-2026-102823
[4] https://security-tracker.debian.org/tracker/CVE-2026-102824
https://www.cve.org/CVERecord?id=CVE-2026-102824
[5] https://security-tracker.debian.org/tracker/CVE-2026-102825
https://www.cve.org/CVERecord?id=CVE-2026-102825
Please adjust the affected versions in the BTS as needed.
More information about the Pkg-rust-maintainers
mailing list