AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-102822.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSLOW / 3.7CVSS 3.1 · security-advisories@github.com
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSDeferredModified Sep 29, 2026

Disclosure summary

Russh is a Rust SSH client and server library. Prior to 0.63.1, a connection configured to permit mac=none can negotiate it with a MAC-requiring CTR or CBC block cipher because the selection logic validates needs_mac() only when MAC selection fails. A remote peer can then send a packet with a decrypted length of zero, causing russh/src/cipher/mod.rs to shrink the previously read block before indexing buffer.buffer[16..], which panics and terminates the connection task. This issue is fixed in version 0.63.1.

Source-reported weakness categories

CWE-129

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-p8qx-h547-fjw9

Open original source · Updated Sep 30, 2026

russh: negotiating a MAC-requiring block cipher (CTR/CBC) with mac=none causes a slice-index-out-of-range panic

Source severity: LOW / 0

EcosystemPackageAffected rangeFirst patched
rustrussh0.63.1
NIST National Vulnerability Database · NVD-CVE-2026-102822

Open original source · Updated Sep 29, 2026

Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.

Original records & references

PUBLISHED 2026-09-29T15:17:24-04:00
MODIFIED 2026-09-29T16:17:17-04:00
INGESTED 2026-10-06T11:43:05-04:00