CVE-2026-102824: falha de média gravidade em Eugeny russh
Russh: Missing X25519 zero-point validation in hybrid ML-KEM key exchange
Publicada em · Atualizada em
13Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 4.3epss 0.1%
probabilidade de exploração
0.1%top 97% das CVEs
exploração observada
nãonenhuma fonte reporta
Russh is a Rust SSH client and server library. Prior to 0.63.0, the hybrid ML-KEM 768 and X25519 implementation in russh/src/kex/hybrid_mlkem.rs accepts an all-zero 32-byte peer X25519 public key in both server_dh and compute_shared_secret, forcing the X25519 contribution to the combined shared secret to zero. A malicious SSH peer can therefore make the combined secret depend only on ML-KEM, defeating the hybrid exchange's intended fallback protection if ML-KEM is later weakened. This issue is fixed in version 0.63.0.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Produtos afetados
Eugeny · russhCVEs relacionadas — Eugeny russh
No mesmo produto, das mais perigosas para as menos.
CVE-2024-43410HIGHRussh has an OOM Denial of Service due to allocation of untrusted amountEPSS 0.9%CVE-2026-42189HIGHRussh: Pre-auth DoS via unbounded allocation in keyboard-interactive authEPSS 0.8%CVE-2026-73430MEDIUMRussh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB)EPSS 0.6%CVE-2026-73429MEDIUMRussh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS)EPSS 0.5%CVE-2026-48108MEDIUMRussh: SSH identification parsing accepted non-canonical client banners and did not bound pre-banner inputEPSS 0.5%CVE-2026-48110HIGHRussh: SSH message fields were decoded through allocation-first parsers before field-specific boundsEPSS 0.5%