<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:russh:russh:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3arusshrussh/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 01 Oct 2026 04:21:44 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3arusshrussh/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Improper Validation of SSH Channel IDs in russh Client</title><link>https://feed.craftedsignal.io/briefs/2026-10-russh-channel-vulnerability/</link><pubDate>Thu, 01 Oct 2026 04:21:44 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-russh-channel-vulnerability/</guid><description>The russh library fails to validate SSH channel IDs for client-side message callbacks, allowing a malicious SSH server to trigger application-level logic errors or denial-of-service via spoofed channel lifecycle events.</description><content:encoded><![CDATA[<p>CVE-2026-102823 describes a security vulnerability in the russh library (versions &lt;= 0.63.0) where client-side processing of channel-scoped SSH messages lacks sufficient validation. While the server-side component of the library was updated to gate messages using <code>is_established_channel()</code>, the client-side implementation in <code>russh/src/client/encrypted.rs</code> incorrectly invokes public <code>Handler</code> trait methods for messages (such as <code>CHANNEL_DATA</code>, <code>CHANNEL_EOF</code>, <code>CHANNEL_CLOSE</code>, and <code>CHANNEL_REQUEST</code>) regardless of whether the <code>channel_num</code> corresponds to an existing, opened channel.</p>
<p>This issue is significant for developers of automation, orchestration, or CI/CD tools that use russh as an SSH client. Applications that trust the library's implicit contract - expecting that <code>Handler</code> callbacks only fire for valid, user-initiated channels - are vulnerable to state desynchronization. A malicious or compromised SSH server can inject spoofed events to manipulate internal application state, such as exit code trackers or completion futures, or trigger application panics if the developer performs unsafe indexing based on the provided channel ID.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker controls or intercepts an SSH server (e.g., a rogue jump host or compromised build server).</li>
<li>Client connects to the malicious server and completes SSH authentication.</li>
<li>Attacker monitors for <code>SSH_MSG_CHANNEL_OPEN</code> or predicts future channel IDs based on the sequential allocation pattern starting at 1.</li>
<li>Attacker transmits spoofed channel-scoped messages (e.g., <code>CHANNEL_REQUEST</code> for <code>exit-status</code> or <code>CHANNEL_CLOSE</code>) referencing an uninitialized or non-existent <code>channel_num</code>.</li>
<li>The vulnerable <code>russh</code> client receives the message in <code>client_read_authenticated</code>.</li>
<li>The library fails to perform a validation check against the known active channels.</li>
<li>The library unconditionally invokes a <code>Handler</code> callback (e.g., <code>client.exit_status(...)</code> or <code>client.channel_close(...)</code>) with the attacker-supplied ID.</li>
<li>Downstream application code processes the callback, leading to state corruption or an unhandled panic (DoS).</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in application-level denial-of-service (panics) or logic integrity violations. Automation tools relying on russh may incorrectly report success/failure of remote commands, leading to flawed deployment outcomes or bypassed security checks in CI/CD pipelines. The vulnerability affects any software utilizing <code>russh</code> versions up to 0.63.0 as an SSH client.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Audit downstream applications using the <code>russh</code> library for logic that assumes the validity of <code>ChannelId</code> values provided via <code>Handler</code> trait methods.</li>
<li>Upgrade the <code>russh</code> library immediately upon the availability of a patched version.</li>
<li>Implement explicit channel validation logic within the <code>Handler</code> trait implementations as an interim defense-in-depth measure, ensuring the application maintains its own set of active, known channels and rejecting callbacks for unknown IDs.</li>
</ol>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category></item></channel></rss>