PT-2026-102805 · Russh · Russh
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Russh versions prior to 0.63.2
Description
An authenticated remote peer can trigger a memory exhaustion condition by sending
SSH MSG KEXINIT without the mandatory SSH MSG KEX ECDH INIT and subsequently flooding SSH MSG CHANNEL OPEN messages. This occurs because SessionKexState::InProgress prevents the priority receiver in russh/src/server/session.rs from being drained. Consequently, the server continues to process network input and enqueues a ChannelOpenReply for every request on an unbounded channel, allowing a single connection to consume memory until the process is terminated.Recommendations
Update to version 0.63.2.
Exploit
Fix
Allocation of Resources Without Limits
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Russh