Local Process Vulnerability in Pageant for Russh Clients
CVE-2026-102820
6.2MEDIUM
What is CVE-2026-102820?
A vulnerability exists in the Windows pageant crate prior to version 0.2.3, where the 'MemoryMap::read' function fails to properly validate a peer-controlled response length. This oversight allows a local process impersonating the Pageant window to manipulate memory allocations, potentially allocating excessive amounts of memory (up to 4 GiB), thus leading to application crashes for russh clients and exposing sensitive adjacent memory areas. Users are encouraged to upgrade to pageant version 0.2.3 to mitigate this issue.
Affected Version(s)
pageant < 0.2.3
russh < 0.63.2
