CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

GHSA-cqjc-rmpq-xprq: Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records

mediumCVSS 4.3
Summary A post-authentication denial-of-service panic in russh 0.62.2 (commit c4be19f1915c8682f4615c3fd50008512b474491, current default branch main as of 2026-07-22). An authenticated client sends a pty-req channel request carrying more than 130 terminal-mode records. The parser uses a fixed [(Pty::TTY_OP_END, 0); 130] array but increments its counter i for every valid record (logging "too many pty codes" without returning), then slices &modes[0..i] — an out-of-bounds slice that panics (`range end index 131 out of range for slice of length 130) before the application pty_request` handler runs. This is reachable with the default server configuration and the default crypto config (curve25519-sha256 + chacha20-poly1305), requiring only an authenticated session channel — no caller-supplied parameter. It is reproduced end-to-end against the unmodified real russh 0.62.2 library (a real russh::client + russh::server over TCP, using the public Channel::request_pty(...) API); the PoC below links the real crate, not a copied snippet. The defect is still present on main HEAD (v0.62.3, 2026-07-22) and is not covered by any of the 11 published russh GHSA advisories (GHSA-4r3c-5hpg-58qr / CVE-2026-48110 is allocation-first string parsing, not the fixed-array slice overflow; it was fixed in 0.61.0 but this code path still overflows the fixed array). Rust bounds-checked panics abort the task safely (no memory corruption / RCE); the impact is remote denial of service. Details russh/src/server/encrypted.rs, pty-req handling (lines 1137–1201): let mut modes = [(Pty::TTY_OP_END, 0); 130]; // fixed 130-entry array (line 1137) let mut i = 0; ... while !mode_bytes.is_empty() { let code = mode_bytes[0]; if code == 0 { if mode_bytes.len() != 1 { return Err(...); } break; } if mode_bytes.len() < 5 { return Err(...); } let num = BigEndian::read_u32(&mode_bytes[1..5]); if let Some(code) = Pty::from_u8(code) { if i < 130 { modes[i] = (code, num); } else { error!("pty-req: too many pty cod

Details

Source
GitHub Security Advisories (INTL · database · site)
Severity
medium — CVSS 4.3
Published
2026-07-24
Last updated
2026-07-24
Exploitation
Not in CISA KEV at last sync

Original advisory: https://github.com/advisories/GHSA-cqjc-rmpq-xprq

More from GitHub Security Advisories