Security Advisory

CVE-2026-48110

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-06-10 20:26:29
Last updated 2026-06-11 16:15:23
Assigner GitHub_M
CVSS score 7.5
State PUBLISHED

Description

Russh is a Rust SSH client & server library. From version 0.34.0 to before version 0.61.0, several russh client and server message handlers decoded attacker-controlled SSH strings, name-lists, and byte fields into owned allocations before applying field-specific bounds. A remote SSH peer could send oversized, high-fanout, or malformed length-prefixed fields and make the library allocate, attempt to allocate, or split data before rejecting input that should have been rejected earlier. This issue has been patched in version 0.61.0.