Executive brief
Russh is a library used to implement SSH (Secure Shell) connections in Rust applications. A vulnerability in how it handles incoming messages allows a remote attacker to force the application to consume excessive amounts of memory, potentially leading to a system crash or service outage. This can occur even before a user has logged in, making it a significant risk for publicly accessible SSH services.
Technical details
The russh library's SSH message handlers for both clients and servers decoded attacker-controlled strings, name-lists, and byte fields into owned allocations (e.g., String, Vec, Bytes) before validating field-specific length bounds. An unauthenticated remote peer can send malformed or oversized length-prefixed fields, such as those in KEXINIT or USERAUTH_REQUEST messages, to trigger large memory allocations. In a high-concurrency scenario, this leads to significant RAM consumption or process termination due to allocator failure. The vulnerability is mitigated in version 0.61.0 by introducing borrowed, bounded parsing helpers that validate lengths before allocation.
Affected products
- Eugeny russh >= 0.34.0, < 0.61.0
Timeline
- 2026-05-20: advisory: Initial GitHub Advisory published
- 2026-06-11: patched: Version 0.61.0 released