Bug 2543503 (CVE-2026-102823)
| Summary: | CVE-2026-102823 russh: russh: State corruption via unverified SSH channel identifiers | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | Keywords: | Security |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in russh, a Secure Shell (SSH) client and server library. When communicating with a client, a malicious SSH server can send channel lifecycle events referencing unverified, unopened, or closed channel identifiers. Because the library forwards these events to client handlers without verifying that the channel was established by the client, this flaw can cause application crashes, resulting in a Denial of Service (DoS), or corrupt command completion and exit status tracking.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-09-29 18:40:38 UTC
|