CVE-2026-102822: russh: negotiating a MAC-requiring block cipher (CTR/CBC) with mac=none causes a slice-index-out-of-range panic
Russh is a Rust SSH client and server library. Prior to 0.63.1, a connection configured to permit mac=none can negotiate it with a MAC-requiring CTR or CBC block cipher because the selection logic validates needsmac() only when MAC selection fails. A remote peer can then send a packet with a decrypted length of zero, causing russh/src/cipher/mod.rs to shrink the previously read block before indexing buffer.buffer[16..], which panics and terminates the connection task. This issue is fixed in version 0.63.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
russhto a version that resolves this vulnerability.Fixed in 0.63.1
Event History
Frequently Asked Questions
Which deployments are exposed to this denial-of-service condition?
Russh versions before 0.63.1 are affected when configured to permit mac=none and when a MAC-requiring CTR or CBC block cipher can be negotiated. The issue can affect uses of Russh as either an SSH client or server.
What must a remote peer do to trigger the failure?
The peer must negotiate mac=none together with a MAC-requiring CTR or CBC cipher, then send a packet whose decrypted length is zero. This reaches an out-of-range slice operation and panics the connection task.
Is a default configuration known to be affected?
The available information identifies configurations that permit mac=none as affected. It does not state whether mac=none is permitted by default.
What mitigation is available if upgrading cannot happen immediately?
Do not permit negotiation of mac=none, particularly alongside CTR or CBC ciphers that require a MAC. Upgrading to russh 0.63.1 fixes the selection logic.