CVE-2026-102821 Details
Description
Russh is a Rust SSH client and server library. Prior to 0.63.2, an authenticated remote peer can send SSH_MSG_KEXINIT without the required SSH_MSG_KEX_ECDH_INIT and then flood SSH_MSG_CHANNEL_OPEN messages while SessionKexState::InProgress prevents priority_receiver in russh/src/server/session.rs from being drained. The server continues processing network input and enqueues a ChannelOpenReply for each request on an unbounded channel, allowing one connection to grow memory until the process is terminated. This issue is fixed in version 0.63.2.
A denial-of-service vulnerability has been identified in the Russh SSH client and server library, specifically in versions prior to 0.63.2. The issue arises when an authenticated remote peer sends an SSH_MSG_KEXINIT message without the accompanying SSH_MSG_KEX_ECDH_INIT. This omission leaves the server's key exchange state in 'InProgress', while the peer floods SSH_MSG_CHANNEL_OPEN messages. The server, unable to drain its message queue, processes these channel open requests on an unbounded channel, leading to excessive memory consumption until the process is terminated.
Users can upgrade to Russh version 0.63.2 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 29, 2026CISA-ADP
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Eugeny/russh/security/advisories/GHSA-35g8-35p8-c8fw | CISA-ADP | AdvisoryExploitRemedyVendor |
| https://github.com/Eugeny/russh/commit/a282af361ac99bc76b80876d1aae128e89dbf66b | [email protected] | Source CodeVendor |
| https://github.com/Eugeny/russh/releases/tag/v0.63.2 | [email protected] | Release NotesVendor |
| https://github.com/Eugeny/russh/security/advisories/GHSA-35g8-35p8-c8fw | [email protected] | AdvisoryExploitRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-400 | Uncontrolled Resource Consumption | [email protected] |
| CWE-770 | Allocation of Resources Without Limits or Throttling | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Eugeny russh | <= 0.63.1 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | CVE Modified | CISA-ADP |
| Sep 29, 2026 | New CVE Received | [email protected] |
Volerion