Local Process Vulnerability in Pageant for Russh Clients
CVE-2026-102820

6.2MEDIUM

Key Information:

Vendor

Eugeny

Vendor
CVE Published:
29 September 2026

What is CVE-2026-102820?

A vulnerability exists in the Windows pageant crate prior to version 0.2.3, where the 'MemoryMap::read' function fails to properly validate a peer-controlled response length. This oversight allows a local process impersonating the Pageant window to manipulate memory allocations, potentially allocating excessive amounts of memory (up to 4 GiB), thus leading to application crashes for russh clients and exposing sensitive adjacent memory areas. Users are encouraged to upgrade to pageant version 0.2.3 to mitigate this issue.

Affected Version(s)

pageant < 0.2.3

russh < 0.63.2

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.