Disclosure summary
Russh is a Rust SSH client and server library. Prior to 0.63.2, an authenticated remote peer can send SSH_MSG_KEXINIT without the required SSH_MSG_KEX_ECDH_INIT and then flood SSH_MSG_CHANNEL_OPEN messages while SessionKexState::InProgress prevents priority_receiver in russh/src/server/session.rs from being drained. The server continues processing network input and enqueues a ChannelOpenReply for each request on an unbounded channel, allowing one connection to grow memory until the process is terminated. This issue is fixed in version 0.63.2.
Source-reported weakness categories
CWE-400, CWE-770
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-35g8-35p8-c8fw
Open original source · Updated Sep 30, 2026
Russh: Unbounded memory exhaustion via CHANNEL_OPEN flood during a client-stalled rekey
Source severity: MEDIUM / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| rust | russh | 0.63.2 |
NIST National Vulnerability Database · NVD-CVE-2026-102821
Open original source · Updated Sep 30, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
Original records & references
PUBLISHED 2026-09-29T15:17:23-04:00
MODIFIED 2026-09-30T16:17:23-04:00
INGESTED 2026-10-06T11:43:05-04:00