Product
The russh library fails to validate SSH channel IDs for client-side message callbacks, allowing a malicious SSH server to trigger application-level logic errors or denial-of-service via spoofed channel lifecycle events.