{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3arusshrussh/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:russh:russh:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-102823"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["russh (\u003c= 0.63.0)"],"_cs_severities":["medium"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["russh"],"content_html":"\u003cp\u003eCVE-2026-102823 describes a security vulnerability in the russh library (versions \u0026lt;= 0.63.0) where client-side processing of channel-scoped SSH messages lacks sufficient validation. While the server-side component of the library was updated to gate messages using \u003ccode\u003eis_established_channel()\u003c/code\u003e, the client-side implementation in \u003ccode\u003erussh/src/client/encrypted.rs\u003c/code\u003e incorrectly invokes public \u003ccode\u003eHandler\u003c/code\u003e trait methods for messages (such as \u003ccode\u003eCHANNEL_DATA\u003c/code\u003e, \u003ccode\u003eCHANNEL_EOF\u003c/code\u003e, \u003ccode\u003eCHANNEL_CLOSE\u003c/code\u003e, and \u003ccode\u003eCHANNEL_REQUEST\u003c/code\u003e) regardless of whether the \u003ccode\u003echannel_num\u003c/code\u003e corresponds to an existing, opened channel.\u003c/p\u003e\n\u003cp\u003eThis issue is significant for developers of automation, orchestration, or CI/CD tools that use russh as an SSH client. Applications that trust the library's implicit contract - expecting that \u003ccode\u003eHandler\u003c/code\u003e callbacks only fire for valid, user-initiated channels - are vulnerable to state desynchronization. A malicious or compromised SSH server can inject spoofed events to manipulate internal application state, such as exit code trackers or completion futures, or trigger application panics if the developer performs unsafe indexing based on the provided channel ID.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker controls or intercepts an SSH server (e.g., a rogue jump host or compromised build server).\u003c/li\u003e\n\u003cli\u003eClient connects to the malicious server and completes SSH authentication.\u003c/li\u003e\n\u003cli\u003eAttacker monitors for \u003ccode\u003eSSH_MSG_CHANNEL_OPEN\u003c/code\u003e or predicts future channel IDs based on the sequential allocation pattern starting at 1.\u003c/li\u003e\n\u003cli\u003eAttacker transmits spoofed channel-scoped messages (e.g., \u003ccode\u003eCHANNEL_REQUEST\u003c/code\u003e for \u003ccode\u003eexit-status\u003c/code\u003e or \u003ccode\u003eCHANNEL_CLOSE\u003c/code\u003e) referencing an uninitialized or non-existent \u003ccode\u003echannel_num\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe vulnerable \u003ccode\u003erussh\u003c/code\u003e client receives the message in \u003ccode\u003eclient_read_authenticated\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe library fails to perform a validation check against the known active channels.\u003c/li\u003e\n\u003cli\u003eThe library unconditionally invokes a \u003ccode\u003eHandler\u003c/code\u003e callback (e.g., \u003ccode\u003eclient.exit_status(...)\u003c/code\u003e or \u003ccode\u003eclient.channel_close(...)\u003c/code\u003e) with the attacker-supplied ID.\u003c/li\u003e\n\u003cli\u003eDownstream application code processes the callback, leading to state corruption or an unhandled panic (DoS).\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in application-level denial-of-service (panics) or logic integrity violations. Automation tools relying on russh may incorrectly report success/failure of remote commands, leading to flawed deployment outcomes or bypassed security checks in CI/CD pipelines. The vulnerability affects any software utilizing \u003ccode\u003erussh\u003c/code\u003e versions up to 0.63.0 as an SSH client.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAudit downstream applications using the \u003ccode\u003erussh\u003c/code\u003e library for logic that assumes the validity of \u003ccode\u003eChannelId\u003c/code\u003e values provided via \u003ccode\u003eHandler\u003c/code\u003e trait methods.\u003c/li\u003e\n\u003cli\u003eUpgrade the \u003ccode\u003erussh\u003c/code\u003e library immediately upon the availability of a patched version.\u003c/li\u003e\n\u003cli\u003eImplement explicit channel validation logic within the \u003ccode\u003eHandler\u003c/code\u003e trait implementations as an interim defense-in-depth measure, ensuring the application maintains its own set of active, known channels and rejecting callbacks for unknown IDs.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-01T04:21:44Z","date_published":"2026-10-01T04:21:44Z","id":"https://feed.craftedsignal.io/briefs/2026-10-russh-channel-vulnerability/","summary":"The russh library fails to validate SSH channel IDs for client-side message callbacks, allowing a malicious SSH server to trigger application-level logic errors or denial-of-service via spoofed channel lifecycle events.","title":"Improper Validation of SSH Channel IDs in russh Client","url":"https://feed.craftedsignal.io/briefs/2026-10-russh-channel-vulnerability/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:russh:russh:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}