CVE-2026-102820 Details
Description
pageant provides a [PageantStream] type that implements [AsyncRead] and [AsyncWrite] traits and can be used to talk to a running Pageant instance. Prior to pageant 0.2.3, the Windows pageant crate's pageant/src/wmmessage.rs MemoryMap::read function trusts a peer-controlled u32 response length supplied through the 8192-byte Pageant shared-memory mapping reached by AgentClient::connect_pageant. A local process that impersonates the Pageant window can make query_pageant_direct allocate up to approximately 4 GiB and copy beyond the mapped view, reliably crashing a russh client and conditionally exposing adjacent committed memory. This issue is fixed in pageant 0.2.3.
A vulnerability in the Pageant Windows crate, specifically in versions through 0.2.2, allows for an out-of-bounds read and unbounded memory allocation. The issue arises in the MemoryMap::read function, which fails to properly validate a peer-controlled response length before reading from a shared-memory mapping. This flaw can be exploited by a local process impersonating the Pageant window, causing a russh client to crash and potentially disclosing adjacent memory.
Users can update to Pageant version 0.2.3, which addresses the vulnerability by adding proper bounds checking to the MemoryMap::read function.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 29, 2026CISA-ADP
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Eugeny/russh/security/advisories/GHSA-g4mp-vgx3-xrvm | CISA-ADP | AdvisoryExploitRemedyVendor |
| https://github.com/Eugeny/russh/commit/5d566989ebabfdebfe6b33243d31765a0812260b | [email protected] | Source CodeVendor |
| https://github.com/Eugeny/russh/releases/tag/v0.63.2 | [email protected] | Release NotesVendor |
| https://github.com/Eugeny/russh/security/advisories/GHSA-g4mp-vgx3-xrvm | [email protected] | AdvisoryExploitRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | [email protected] |
| CWE-789 | Memory Allocation with Excessive Size Value | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Eugeny russh | All versions |
CPE
Remediation
| |
| Eugeny russh-pageant | <= 0.2.2 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | CVE Modified | CISA-ADP |
| Sep 29, 2026 | New CVE Received | [email protected] |
Volerion