Threat Advisory

russh Flaws Enable Session Spoofing and Resource Consumption

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting russh have been identified, with potential for malicious peers to force the X25519 contribution to zero, reducing the hybrid KEX to a single-algorithm exchange.[/subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting russh have been identified, with potential for malicious peers to force the X25519 contribution to zero, reducing the hybrid KEX to a single-algorithm exchange.[emaillocker id="1283"]

CVE-2026-102824 (CVSS 4.3 — Medium): A remote peer can force the X25519 contribution to the combined shared secret to zero by sending a valid ML-KEM 768 encapsulation key followed by 32 zero bytes as the X25519 component, reducing security to depend solely on ML-KEM.

CVE-2026-102823 (CVSS 7.5 — High): A russh client-side channel validation flaw allows malicious SSH servers to send messages for arbitrary channel_num values, triggering Handler callbacks such as client.exit_status(...), client.channel_close(...), and client.channel_success(...) without Session::is_established_channel() validation, potentially causing channel-state manipulation and application-level denial of service.

CVE-2026-102821(CVSS 6.5 — Medium): A resource-management flaw in the russh server allows a peer to repeatedly send SSH_MSG_KEX_ECDH_INIT messages while key re-exchange remains in SessionKexState::InProgress, causing an unbounded queue of SSH_MSG_CHANNEL_OPEN messages and potentially exhausting server memory.

 

RECOMMENDATIONS:

 

REFERENCES:

The following reports contain further technical details:
https://github.com/advisories/GHSA-w3jg-pjxf-73p4
https://github.com/advisories/GHSA-47hw-gvq5-r2gm
https://github.com/advisories/GHSA-35g8-35p8-c8fw

[/emaillocker]
crossmenu