CVE-2025-54804: Russh is missing an overflow check during channel windows adjust
Summary The channel window adjust message of the SSH protocol is used to track the free space in the receive buffer of the other side of a channel. The current implementation takes the value from the message and adds it to an internal state value. This can result in a integer overflow. If the Rust code is compiled with overflow checks, it will panic. A malicious client can crash a server.
Details According https://datatracker.ietf.org/doc/html/rfc4254#section-5.2, The value must not overflow. The incorrect handling is done in server/encrypted.rs and client/encrypted.rs in the handling of CHANNELWINDOWADJUST.
let amount = maperr!(u32::decode(&mut r))?; ... channel.recipientwindowsize += amount;
It could be replaced with something like
if let Some(ref mut channel) = enc.channels.getmut(&channelnum) { // rfc 4254: The window MUST NOT be increased above 2^32 - 1 bytes. newsize = channel.recipientwindowsize.saturatingadd(amount); channel.recipientwindowsize = newsize; } ...
PoC A customized client code would be required to send a message with a big value like u32max. Not done yet.
Impact This problem seems only critical to a server. One user can crash the server, which might take down the service. A malicious server could also crash a single client, but this seems not very critical.
Other sources
Russh is a Rust SSH client & server library. In versions 0.54.0 and below, the channel window adjust message of the SSH protocol is used to track the free space in the receive buffer of the other side of a channel. The current implementation takes the value from the message and adds it to an internal state value. This can result in a integer overflow. If the Rust code is compiled with overflow checks, it will panic. A malicious client can crash a server. This is fixed in version 0.54.1.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54804?
CVE-2025-54804 is classified as a medium severity vulnerability due to the potential for integer overflow leading to exploit possibilities.
How do I fix CVE-2025-54804?
To fix CVE-2025-54804, upgrade to rust/russh version 0.54.1 or later to address the integer overflow issue.
What types of software are affected by CVE-2025-54804?
CVE-2025-54804 affects the rust/russh package, particularly versions prior to 0.54.1.
What is the impact of CVE-2025-54804?
The impact of CVE-2025-54804 includes potential remote code execution through exploited integer overflow vulnerabilities.
Is there a public exploit for CVE-2025-54804?
As of now, there are no confirmed public exploits specifically targeting CVE-2025-54804.