CVE-2026-102822 Details
Description
Russh is a Rust SSH client and server library. Prior to 0.63.1, a connection configured to permit mac=none can negotiate it with a MAC-requiring CTR or CBC block cipher because the selection logic validates needs_mac() only when MAC selection fails. A remote peer can then send a packet with a decrypted length of zero, causing russh/src/cipher/mod.rs to shrink the previously read block before indexing buffer.buffer[16..], which panics and terminates the connection task. This issue is fixed in version 0.63.1.
A denial-of-service vulnerability has been identified in the Russh SSH client and server library, affecting versions through 0.63.0. The issue arises when a connection is configured to allow 'mac=none', which can be negotiated with a MAC-requiring block cipher, such as those using CTR or CBC modes. This improper negotiation allows a remote peer to send a packet with a decrypted length of zero, causing a buffer underflow that triggers a panic and terminates the connection. The vulnerability is rooted in the MAC selection logic, which fails to validate the compatibility of negotiated MACs with the requirements of selected ciphers.
Users can update to Russh version 0.63.1 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 29, 2026CISA-ADP
Assessed Sep 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Eugeny/russh/security/advisories/GHSA-p8qx-h547-fjw9 | CISA-ADP | AdvisoryExploitRemedyVendor |
| https://github.com/Eugeny/russh/commit/2885385abfee279092a41d80c6cb6ac367353159 | [email protected] | Source CodeVendor |
| https://github.com/Eugeny/russh/releases/tag/v0.63.1 | [email protected] | Release NotesVendor |
| https://github.com/Eugeny/russh/security/advisories/GHSA-p8qx-h547-fjw9 | [email protected] | AdvisoryExploitRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-129 | Improper Validation of Array Index | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Eugeny russh | <= 0.63.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 29, 2026 | CVE Modified | CISA-ADP |
| Sep 29, 2026 | New CVE Received | [email protected] |
Volerion