Memory Flooding Vulnerability in Russh SSH Client and Server Library
CVE-2026-102821
6.5MEDIUM
What is CVE-2026-102821?
The Russh SSH client and server library is vulnerable to a memory flooding issue that arises when an authenticated remote peer sends SSH_MSG_KEXINIT without the necessary SSH_MSG_KEX_ECDH_INIT. This allows the peer to overwhelm the server with an unbounded number of SSH_MSG_CHANNEL_OPEN messages while in the SessionKexState::InProgress state. As a result, the server continues processing these messages, leading to potential memory exhaustion that could crash the process. This vulnerability has been addressed in version 0.63.2.
Affected Version(s)
russh < 0.63.2
