CVE-2026-102824: Russh: Missing X25519 zero-point validation in hybrid ML-KEM key exchange
Russh is a Rust SSH client and server library. Prior to 0.63.0, the hybrid ML-KEM 768 and X25519 implementation in russh/src/kex/hybridmlkem.rs accepts an all-zero 32-byte peer X25519 public key in both serverdh and computesharedsecret, forcing the X25519 contribution to the combined shared secret to zero. A malicious SSH peer can therefore make the combined secret depend only on ML-KEM, defeating the hybrid exchange's intended fallback protection if ML-KEM is later weakened. This issue is fixed in version 0.63.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
russhto a version that resolves this vulnerability.Fixed in 0.63.0
Event History
Frequently Asked Questions
Which deployments are exposed?
Russh SSH clients and servers using the hybrid ML-KEM 768 and X25519 key exchange are affected when running versions earlier than 0.63.0. The issue can be triggered by a malicious SSH peer.
What does an attacker need to do to exploit this?
The attacker needs to act as the SSH peer and provide an all-zero 32-byte X25519 public key during the hybrid key exchange. No user interaction is required, but the CVSS vector indicates the attacker has low privileges.
What is the security impact of a successful attack?
The X25519 portion of the combined secret is forced to zero, leaving the combined secret dependent only on ML-KEM. This removes the hybrid exchange's intended fallback protection if ML-KEM is weakened in the future.
What should teams do to remediate the issue?
Upgrade russh to version 0.63.0 or later, which fixes the missing zero-point validation. The provided data does not specify an alternative mitigation for environments that cannot upgrade immediately.