Post-auth Remote Panic Vulnerability in russh 0.62.2
An early warning has been issued regarding a potential post-authentication denial-of-service vulnerability in russh version 0.62.2. This vulnerability reportedly allows an authenticated client to cause a panic by sending more than 130 terminal-mode records, leading to a remote denial of service.
What happened
According to the initial advisory, russh version 0.62.2 appears to be susceptible to a post-authentication denial-of-service attack. An authenticated client can allegedly trigger a panic by sending a pty-req message with more than 130 terminal-mode records. This results in an out-of-bounds slice, causing the application to panic and leading to a denial of service.
Professional software engineers using russh 0.62.2 are advised to monitor for updates from the maintainers that address this vulnerability. As a temporary mitigation, consider using a version prior to 0.62.2 if immediate action is required. The severity of this issue is currently classified as high, and the incident is under investigation. For more detailed information, consult the primary sources linked in the advisory.
How 0Day mitigates this
russh is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.