PT-2026-102806 · Pypi · Russh

·

CVE-2026-102822

·

Published

2026-09-29

·

Updated

2026-09-29

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Russh versions prior to 0.63.1
Description A connection configured to permit mac=none can negotiate it with a MAC-requiring CTR or CBC block cipher because the selection logic validates needs mac() only when MAC selection fails. A remote peer can send a packet with a decrypted length of zero, causing the russh/src/cipher/mod.rs file to shrink the previously read block before indexing buffer.buffer[16..], which results in a panic and terminates the connection task.
Recommendations Update to version 0.63.1.

Exploit

Fix

Improper Validation of Array Index

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102822
GHSA-P8QX-H547-FJW9

Affected Products

Russh