PT-2026-102804 · Pageant · Pageant
CVSS v3.1
6.2
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
pageant versions prior to 0.2.3
Description
The
MemoryMap::read function in the pageant/src/wmmessage.rs file trusts a peer-controlled u32 response length provided via the 8192-byte shared-memory mapping accessed by AgentClient::connect pageant. A local process impersonating the Pageant window can cause query pageant direct to allocate approximately 4 GiB of memory and copy data beyond the mapped view. This can lead to a crash of a russh client and potentially expose adjacent committed memory.Recommendations
Update to version 0.2.3.
Exploit
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pageant