CVE-2026-102822
Deferred Deferred - Pending Action

SSH Connection Task Termination via Zero-Length Packet in Russh

Vulnerability report for CVE-2026-102822, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: GitHub, Inc.

Description

Russh is a Rust SSH client and server library. Prior to 0.63.1, a connection configured to permit mac=none can negotiate it with a MAC-requiring CTR or CBC block cipher because the selection logic validates needs_mac() only when MAC selection fails. A remote peer can then send a packet with a decrypted length of zero, causing russh/src/cipher/mod.rs to shrink the previously read block before indexing buffer.buffer[16..], which panics and terminates the connection task. This issue is fixed in version 0.63.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
russh russh to 0.63.1 (exc)
eugeny russh to 0.63.1 (exc)
eugeny russh 0.63.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-129 The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the russh SSH library versions before 0.63.1. It involves a flaw in MAC (Message Authentication Code) negotiation where a connection allowing mac=none can incorrectly negotiate it with a MAC-requiring cipher like AES-CTR or AES-CBC. This happens because the selection logic only checks the needs_mac() requirement when MAC selection fails, not during normal negotiation. An attacker can exploit this by sending a packet with a decrypted length of zero, causing a buffer underflow panic in the connection task.

Detection Guidance

Check if your SSH server or client uses russh library versions <= 0.63.0 and has mac=none configured. Inspect SSH configuration files for mac=none settings and verify russh version with commands like 'cargo tree | grep russh' or 'russh --version'.

Impact Analysis

This vulnerability can cause denial-of-service (DoS) attacks by terminating SSH connection tasks. An attacker can disrupt active SSH sessions without needing further interaction after the initial exploit. The impact is limited to sessions using non-default configurations where mac=none is included in the preferred MAC list.

Mitigation Strategies

Upgrade russh to version 0.63.1 or later. Remove mac=none from SSH configuration files. Ensure MAC selection logic enforces that ciphers requiring integrity checks never negotiate mac=none.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102822. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart