Threat Advisory

Russh Flaw Lets Authenticated Clients Bypass Channel-Open Policy

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Medium
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A medium-severity vulnerability affecting russh versions <= 0.62.4, tracked as CVE-2026-68930, affects russh versions prior to 0.62.5. The flaw is a server-side channel state issue where the application dispatches channel-scoped handler callbacks for recipient channel IDs that were never opened or confirmed. This can allow an authenticated client to bypass the server application's channel-open policy and potentially execute malicious code. The business impact depends on the downstream application, but in a proof-of-concept, the protected exec_request action ran even though no channel was opened. The vulnerability is not an authentication bypass, as a valid login is required, but rather a failure to enforce the SSH channel lifecycle before delivering channel-scoped callbacks to the application.

RECOMMENDATION:

We recommend you to update russh to version 0.62.5.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A medium-severity vulnerability affecting russh versions <= 0.62.4, tracked as CVE-2026-68930, affects russh versions prior to 0.62.5. The flaw is a server-side channel state issue where the application dispatches channel-scoped handler callbacks for recipient channel IDs that were never opened or confirmed. This can allow an authenticated client to bypass the server application's channel-open policy and potentially execute malicious code. The business impact depends on the downstream application, but in a proof-of-concept, the protected exec_request action ran even though no channel was opened. The vulnerability is not an authentication bypass, as a valid login is required, but rather a failure to enforce the SSH channel lifecycle before delivering channel-scoped callbacks to the application.

RECOMMENDATION:

We recommend you to update russh to version 0.62.5.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu