CVE-2026-102823: russh: Client-side channel-scoped Handler callbacks fire for channel IDs the client never opened
Russh is a Rust SSH client and server library. Prior to 0.63.1, clientreadauthenticated in russh/src/client/encrypted.rs forwards CHANNELDATA, CHANNELEXTENDEDDATA, CHANNELEOF, CHANNELCLOSE, CHANNELOPENFAILURE, CHANNELSUCCESS, CHANNELFAILURE, and CHANNELREQUEST subtypes exit-status, exit-signal, and xon-xoff to public client::Handler callbacks without confirming that the ChannelId belongs to a channel the client opened and established. A malicious SSH server can send lifecycle events for predicted, unopened, unconfirmed, or released channel identifiers, causing application panics or corrupting command completion and exit-code tracking. This issue is fixed in version 0.63.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
russhto a version that resolves this vulnerability.Fixed in 0.63.1
Event History
Frequently Asked Questions
Who can exploit this issue?
A malicious SSH server can exploit a vulnerable Russh client. The server does not need credentials or user interaction to send the affected channel lifecycle and data events.
What is the practical impact on client applications?
Applications may panic, or their command-completion and exit-code tracking can be corrupted when callbacks receive events for channel IDs the client did not open, establish, or has already released.
Which channel messages are affected?
Affected messages include CHANNEL_DATA, CHANNEL_EXTENDED_DATA, CHANNEL_EOF, CHANNEL_CLOSE, CHANNEL_OPEN_FAILURE, CHANNEL_SUCCESS, CHANNEL_FAILURE, and CHANNEL_REQUEST subtypes for exit-status, exit-signal, and xon-xoff.
What versions should be remediated?
The issue affects Russh versions before 0.63.1. Upgrade to version 0.63.1 or later.