DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-102820: CVE-2026-102820: Out-of-Bounds Read and Excessive Memory Allocation in russh pageant

CVE-2026-102820: Out-of-Bounds Read and Excessive Memory Allocation in russh pageant

Vulnerability ID: CVE-2026-102820
CVSS Score: 6.2
Published: 2026-09-30

A critical memory handling vulnerability exists in the pageant crate, a workspace component of the Rust-based russh SSH client library, during communication with the PuTTY Pageant SSH agent on Windows systems. Prior to version 0.2.3, the library's shared memory parsing logic blindly trusted a peer-controlled, 32-bit big-endian response length field. This allows local attackers running within the same user session to trigger out-of-bounds reads or execute an out-of-memory crash of the client application.

TL;DR

Unvalidated 32-bit response length fields in the pageant crate allow a local process to cause an out-of-memory crash or perform out-of-bounds reads against russh-based clients.


Technical Details

  • CWE ID: CWE-125, CWE-789
  • Attack Vector: Local
  • CVSS v3.1 Score: 6.2 (Medium)
  • EPSS Score: 0.00129 (0.129% probability)
  • Impact: Denial of Service (DoS) and potential Information Disclosure
  • Exploit Status: poc
  • KEV Status: Not Listed

Affected Systems

  • pageant crate on Windows operating systems
  • russh client library integrations on Windows operating systems
  • pageant: < 0.2.3 (Fixed in: 0.2.3)
  • russh: >= 0.58.0, < 0.63.2 (Fixed in: 0.63.2)

Code Analysis

Commit: 5d56698

Fix out of bounds read in pageant

Mitigation Strategies

  • Update the cargo project dependencies immediately to use patched versions of the pageant and russh libraries.
  • Isolate automated SSH tasks on Windows within separate containerized virtual contexts to avoid local window messaging interference.
  • Utilize cargo-audit in build pipelines to block deployment of vulnerable dependencies.

Remediation Steps:

  1. Locate the cargo workspace file containing dependencies on the pageant or russh crates.
  2. Run 'cargo update -p pageant' and 'cargo update -p russh' to update to fixed versions.
  3. Verify that pageant is updated to at least 0.2.3 and russh is updated to at least 0.63.2.
  4. Run 'cargo audit' to ensure that no further references to the vulnerable library versions remain in your local dependency trees.

References


Read the full report for CVE-2026-102820 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)