CVE-2025-54804: Russh is missing an overflow check during channel windows adjust

Published Aug 4, 2025
·
Updated

Summary The channel window adjust message of the SSH protocol is used to track the free space in the receive buffer of the other side of a channel. The current implementation takes the value from the message and adds it to an internal state value. This can result in a integer overflow. If the Rust code is compiled with overflow checks, it will panic. A malicious client can crash a server.

Details According https://datatracker.ietf.org/doc/html/rfc4254#section-5.2, The value must not overflow. The incorrect handling is done in server/encrypted.rs and client/encrypted.rs in the handling of CHANNELWINDOWADJUST.

let amount = maperr!(u32::decode(&mut r))?; ... channel.recipientwindowsize += amount;

It could be replaced with something like

if let Some(ref mut channel) = enc.channels.getmut(&channelnum) { // rfc 4254: The window MUST NOT be increased above 2^32 - 1 bytes. newsize = channel.recipientwindowsize.saturatingadd(amount); channel.recipientwindowsize = newsize; } ...

PoC A customized client code would be required to send a message with a big value like u32max. Not done yet.

Impact This problem seems only critical to a server. One user can crash the server, which might take down the service. A malicious server could also crash a single client, but this seems not very critical.

Other sources

Russh is a Rust SSH client & server library. In versions 0.54.0 and below, the channel window adjust message of the SSH protocol is used to track the free space in the receive buffer of the other side of a channel. The current implementation takes the value from the message and adds it to an internal state value. This can result in a integer overflow. If the Rust code is compiled with overflow checks, it will panic. A malicious client can crash a server. This is fixed in version 0.54.1.

MITRE

Affected Software

3 affected componentsFixes available
rust/russh<0.54.1
0.54.1
Russh Project Russh Rust<0.54.1
Warpgate Project Warpgate<0.16.0

Event History

Aug 4, 2025
Advisory Published
via GitHub·08:28 PM
Data Sourced
via GitHub·08:28 PM
DescriptionSeverityWeaknessAffected Software
Aug 5, 2025
CVE Published
via MITRE·12:05 AM
Data Sourced
via MITRE·12:05 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 AM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-54804?

CVE-2025-54804 is classified as a medium severity vulnerability due to the potential for integer overflow leading to exploit possibilities.

2

How do I fix CVE-2025-54804?

To fix CVE-2025-54804, upgrade to rust/russh version 0.54.1 or later to address the integer overflow issue.

3

What types of software are affected by CVE-2025-54804?

CVE-2025-54804 affects the rust/russh package, particularly versions prior to 0.54.1.

4

What is the impact of CVE-2025-54804?

The impact of CVE-2025-54804 includes potential remote code execution through exploited integer overflow vulnerabilities.

5

Is there a public exploit for CVE-2025-54804?

As of now, there are no confirmed public exploits specifically targeting CVE-2025-54804.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203