Improper Validation of SSH Channel IDs in russh Client
The russh library fails to validate SSH channel IDs for client-side message callbacks, allowing a malicious SSH server to trigger application-level logic errors or denial-of-service via spoofed channel lifecycle events.
CVE search metadata
CVE search record: CVE-2026-102823. Severity: high. CVSS: 7.5. KEV: no. Product: russh (<= 0.63.0). Brief: Improper Validation of SSH Channel IDs in russh Client. Brief link: https://feed.craftedsignal.io/briefs/2026-10-russh-channel-vulnerability/
CVE-2026-102823 describes a security vulnerability in the russh library (versions <= 0.63.0) where client-side processing of channel-scoped SSH messages lacks sufficient validation. While the server-side component of the library was updated to gate messages using is_established_channel(), the client-side implementation in russh/src/client/encrypted.rs incorrectly invokes public Handler trait methods for messages (such as CHANNEL_DATA, CHANNEL_EOF, CHANNEL_CLOSE, and CHANNEL_REQUEST) regardless of whether the channel_num corresponds to an existing, opened channel.
This issue is significant for developers of automation, orchestration, or CI/CD tools that use russh as an SSH client. Applications that trust the library's implicit contract - expecting that Handler callbacks only fire for valid, user-initiated channels - are vulnerable to state desynchronization. A malicious or compromised SSH server can inject spoofed events to manipulate internal application state, such as exit code trackers or completion futures, or trigger application panics if the developer performs unsafe indexing based on the provided channel ID.
Attack Chain
- Attacker controls or intercepts an SSH server (e.g., a rogue jump host or compromised build server).
- Client connects to the malicious server and completes SSH authentication.
- Attacker monitors for
SSH_MSG_CHANNEL_OPENor predicts future channel IDs based on the sequential allocation pattern starting at 1. - Attacker transmits spoofed channel-scoped messages (e.g.,
CHANNEL_REQUESTforexit-statusorCHANNEL_CLOSE) referencing an uninitialized or non-existentchannel_num. - The vulnerable
russhclient receives the message inclient_read_authenticated. - The library fails to perform a validation check against the known active channels.
- The library unconditionally invokes a
Handlercallback (e.g.,client.exit_status(...)orclient.channel_close(...)) with the attacker-supplied ID. - Downstream application code processes the callback, leading to state corruption or an unhandled panic (DoS).
Impact
Successful exploitation results in application-level denial-of-service (panics) or logic integrity violations. Automation tools relying on russh may incorrectly report success/failure of remote commands, leading to flawed deployment outcomes or bypassed security checks in CI/CD pipelines. The vulnerability affects any software utilizing russh versions up to 0.63.0 as an SSH client.
Recommendation
- Audit downstream applications using the
russhlibrary for logic that assumes the validity ofChannelIdvalues provided viaHandlertrait methods. - Upgrade the
russhlibrary immediately upon the availability of a patched version. - Implement explicit channel validation logic within the
Handlertrait implementations as an interim defense-in-depth measure, ensuring the application maintains its own set of active, known channels and rejecting callbacks for unknown IDs.
Immediate actions
Inventory all internal tools and services utilizing the russh library version 0.63.0 or earlier.
Mitigations
Upgrade russh to 0.63.1 or later
CVE-2026-102823