CVE-2026-102824 Details
Description
Russh is a Rust SSH client and server library. Prior to 0.63.0, the hybrid ML-KEM 768 and X25519 implementation in russh/src/kex/hybrid_mlkem.rs accepts an all-zero 32-byte peer X25519 public key in both server_dh and compute_shared_secret, forcing the X25519 contribution to the combined shared secret to zero. A malicious SSH peer can therefore make the combined secret depend only on ML-KEM, defeating the hybrid exchange's intended fallback protection if ML-KEM is later weakened. This issue is fixed in version 0.63.0.
A vulnerability exists in the Russh SSH client and server library, specifically in versions prior to 0.63.0. The issue arises in the hybrid ML-KEM 768 and X25519 key exchange implementation, where the library fails to validate that the remote peer's X25519 public key is not the zero point (an all-zero 32-byte value). This oversight allows a malicious SSH peer to nullify the X25519 contribution to the shared secret, effectively reducing the hybrid key exchange to rely solely on ML-KEM. Such an action undermines the intended fallback protection of the hybrid exchange, especially if ML-KEM is later found to be weak.
Users can upgrade to Russh version 0.63.0 or later, where this vulnerability has been addressed. In the patched version, zero-point validation has been added to the hybrid ML-KEM and X25519 key exchange implementation, ensuring that all public keys are properly validated before being used in the key exchange process.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 29, 2026CISA-ADP
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Eugeny/russh/commit/8da8967f196472576b1565d518a0ed60fce60f0c | [email protected] | Source CodeVendor |
| https://github.com/Eugeny/russh/releases/tag/v0.63.0 | [email protected] | Release NotesVendor |
| https://github.com/Eugeny/russh/security/advisories/GHSA-w3jg-pjxf-73p4 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-327 | Use of a Broken or Risky Cryptographic Algorithm | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Eugeny russh | <= 0.63.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | CVE Modified | CISA-ADP |
| Sep 29, 2026 | New CVE Received | [email protected] |
Volerion