Rust SSH Client/Server Library Vulnerability in Russh
CVE-2026-102822
3.7LOW
What is CVE-2026-102822?
Russh, a Rust-based SSH client and server library, allows an attacker to exploit a flaw in the MAC handling mechanism prior to version 0.63.1. When a connection permits mac=none, it incorrectly negotiates with block ciphers that require a MAC. This results in a scenario where a remote peer can trigger a panic by sending a packet with a decrypted length of zero, leading the library to attempt to access a part of the buffer incorrectly, ultimately terminating the connection task. The vulnerability has been addressed in version 0.63.1.
Affected Version(s)
russh < 0.63.1
