CVE-2026-102820: pageant: Out-of-bounds read / oversized allocation in `pageant` MemoryMap::read via a malicious Pageant agent (Windows)
pageant provides a [PageantStream] type that implements [AsyncRead] and [AsyncWrite] traits and can be used to talk to a running Pageant instance. Prior to pageant 0.2.3, the Windows pageant crate's pageant/src/wmmessage.rs MemoryMap::read function trusts a peer-controlled u32 response length supplied through the 8192-byte Pageant shared-memory mapping reached by AgentClient::connectpageant. A local process that impersonates the Pageant window can make querypageantdirect allocate up to approximately 4 GiB and copy beyond the mapped view, reliably crashing a russh client and conditionally exposing adjacent committed memory. This issue is fixed in pageant 0.2.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pageantto a version that resolves this vulnerability.Fixed in 0.2.3
Event History
Frequently Asked Questions
Which systems and applications are exposed?
The issue affects Windows applications using the pageant crate before version 0.2.3 and connecting to a Pageant instance through its PageantStream support. A russh client is specifically identified as reliably crashable.
What does an attacker need to exploit this?
An attacker needs to run a local process that can impersonate the Pageant window. The malicious agent then supplies a peer-controlled response length through the Pageant shared-memory mapping.
What is the practical impact?
A malicious response can cause an allocation of up to approximately 4 GiB and a copy beyond the mapped memory view. This reliably crashes a russh client and may conditionally expose adjacent committed memory.
What version fixes the issue?
Upgrade the pageant crate to version 0.2.3 or later.