CVE-2026-102823 Details
Description
Russh is a Rust SSH client and server library. Prior to 0.63.1, client_read_authenticated in russh/src/client/encrypted.rs forwards CHANNEL_DATA, CHANNEL_EXTENDED_DATA, CHANNEL_EOF, CHANNEL_CLOSE, CHANNEL_OPEN_FAILURE, CHANNEL_SUCCESS, CHANNEL_FAILURE, and CHANNEL_REQUEST subtypes exit-status, exit-signal, and xon-xoff to public client::Handler callbacks without confirming that the ChannelId belongs to a channel the client opened and established. A malicious SSH server can send lifecycle events for predicted, unopened, unconfirmed, or released channel identifiers, causing application panics or corrupting command completion and exit-code tracking. This issue is fixed in version 0.63.1.
A vulnerability exists in the Russh SSH client and server library, specifically in versions prior to 0.63.1. The issue arises in the 'client_read_authenticated' function, where certain channel-related messages from the server are forwarded to public 'client::Handler' callbacks without verifying if the channel ID is valid or has been opened by the client. This flaw allows a malicious SSH server to send events for unconfirmed or already closed channels, leading to application panics or disrupting command tracking and completion processes. The vulnerability has been addressed in version 0.63.1.
Users can upgrade to Russh version 0.63.1 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Eugeny/russh/commit/3430fd26ecafc0dc3705210f5f39a9119fa22774 | [email protected] | Source CodeVendor |
| https://github.com/Eugeny/russh/releases/tag/v0.63.1 | [email protected] | Release NotesVendor |
| https://github.com/Eugeny/russh/security/advisories/GHSA-47hw-gvq5-r2gm | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Eugeny russh | <= 0.63.0 (semver) |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 29, 2026 | New CVE Received | [email protected] |
Volerion