Skip to content
Threat Feed
medium advisory

Improper Validation of SSH Channel IDs in russh Client

The russh library fails to validate SSH channel IDs for client-side message callbacks, allowing a malicious SSH server to trigger application-level logic errors or denial-of-service via spoofed channel lifecycle events.

CVE search metadata

CVE search record: CVE-2026-102823. Severity: high. CVSS: 7.5. KEV: no. Product: russh (<= 0.63.0). Brief: Improper Validation of SSH Channel IDs in russh Client. Brief link: https://feed.craftedsignal.io/briefs/2026-10-russh-channel-vulnerability/

CVE-2026-102823 describes a security vulnerability in the russh library (versions <= 0.63.0) where client-side processing of channel-scoped SSH messages lacks sufficient validation. While the server-side component of the library was updated to gate messages using is_established_channel(), the client-side implementation in russh/src/client/encrypted.rs incorrectly invokes public Handler trait methods for messages (such as CHANNEL_DATA, CHANNEL_EOF, CHANNEL_CLOSE, and CHANNEL_REQUEST) regardless of whether the channel_num corresponds to an existing, opened channel.

This issue is significant for developers of automation, orchestration, or CI/CD tools that use russh as an SSH client. Applications that trust the library's implicit contract - expecting that Handler callbacks only fire for valid, user-initiated channels - are vulnerable to state desynchronization. A malicious or compromised SSH server can inject spoofed events to manipulate internal application state, such as exit code trackers or completion futures, or trigger application panics if the developer performs unsafe indexing based on the provided channel ID.

Attack Chain

  1. Attacker controls or intercepts an SSH server (e.g., a rogue jump host or compromised build server).
  2. Client connects to the malicious server and completes SSH authentication.
  3. Attacker monitors for SSH_MSG_CHANNEL_OPEN or predicts future channel IDs based on the sequential allocation pattern starting at 1.
  4. Attacker transmits spoofed channel-scoped messages (e.g., CHANNEL_REQUEST for exit-status or CHANNEL_CLOSE) referencing an uninitialized or non-existent channel_num.
  5. The vulnerable russh client receives the message in client_read_authenticated.
  6. The library fails to perform a validation check against the known active channels.
  7. The library unconditionally invokes a Handler callback (e.g., client.exit_status(...) or client.channel_close(...)) with the attacker-supplied ID.
  8. Downstream application code processes the callback, leading to state corruption or an unhandled panic (DoS).

Impact

Successful exploitation results in application-level denial-of-service (panics) or logic integrity violations. Automation tools relying on russh may incorrectly report success/failure of remote commands, leading to flawed deployment outcomes or bypassed security checks in CI/CD pipelines. The vulnerability affects any software utilizing russh versions up to 0.63.0 as an SSH client.

Recommendation

  1. Audit downstream applications using the russh library for logic that assumes the validity of ChannelId values provided via Handler trait methods.
  2. Upgrade the russh library immediately upon the availability of a patched version.
  3. Implement explicit channel validation logic within the Handler trait implementations as an interim defense-in-depth measure, ensuring the application maintains its own set of active, known channels and rejecting callbacks for unknown IDs.

Immediate actions

Inventory all internal tools and services utilizing the russh library version 0.63.0 or earlier.

Security Operations 48h

Mitigations

Upgrade russh to 0.63.1 or later

immediate Development

CVE-2026-102823