PT-2026-102808 · Russh · Russh
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Russh versions prior to 0.63.0
Description
The hybrid ML-KEM 768 and X25519 implementation in
russh/src/kex/hybrid mlkem.rs accepts an all-zero 32-byte peer X25519 public key within the server dh() and compute shared secret() functions. This allows a malicious SSH peer to force the X25519 contribution to the combined shared secret to zero, making the secret depend solely on ML-KEM. This behavior bypasses the intended fallback protection of the hybrid exchange, which is designed to maintain security if ML-KEM is compromised.Recommendations
Update to version 0.63.0.
Exploit
Fix
Use of a Broken Cryptographic Algorithm
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Russh