CVE-2026-102820: Out-of-Bounds Read and Excessive Memory Allocation in russh pageant
Vulnerability ID: CVE-2026-102820
CVSS Score: 6.2
Published: 2026-09-30
A critical memory handling vulnerability exists in the pageant crate, a workspace component of the Rust-based russh SSH client library, during communication with the PuTTY Pageant SSH agent on Windows systems. Prior to version 0.2.3, the library's shared memory parsing logic blindly trusted a peer-controlled, 32-bit big-endian response length field. This allows local attackers running within the same user session to trigger out-of-bounds reads or execute an out-of-memory crash of the client application.
TL;DR
Unvalidated 32-bit response length fields in the pageant crate allow a local process to cause an out-of-memory crash or perform out-of-bounds reads against russh-based clients.
Technical Details
- CWE ID: CWE-125, CWE-789
- Attack Vector: Local
- CVSS v3.1 Score: 6.2 (Medium)
- EPSS Score: 0.00129 (0.129% probability)
- Impact: Denial of Service (DoS) and potential Information Disclosure
- Exploit Status: poc
- KEV Status: Not Listed
Affected Systems
- pageant crate on Windows operating systems
- russh client library integrations on Windows operating systems
-
pageant: < 0.2.3 (Fixed in:
0.2.3) -
russh: >= 0.58.0, < 0.63.2 (Fixed in:
0.63.2)
Code Analysis
Commit: 5d56698
Fix out of bounds read in pageant
Mitigation Strategies
- Update the cargo project dependencies immediately to use patched versions of the pageant and russh libraries.
- Isolate automated SSH tasks on Windows within separate containerized virtual contexts to avoid local window messaging interference.
- Utilize cargo-audit in build pipelines to block deployment of vulnerable dependencies.
Remediation Steps:
- Locate the cargo workspace file containing dependencies on the pageant or russh crates.
- Run 'cargo update -p pageant' and 'cargo update -p russh' to update to fixed versions.
- Verify that pageant is updated to at least 0.2.3 and russh is updated to at least 0.63.2.
- Run 'cargo audit' to ensure that no further references to the vulnerable library versions remain in your local dependency trees.
References
Read the full report for CVE-2026-102820 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)