<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T23:59:23.749921+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-352966</id>
    <title>EUVD-2026-352966</title>
    <updated>2026-10-05T23:59:23.839647+00:00</updated>
    <content>EUVD-2026-352966</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-352966"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-73429</id>
    <title>fkie_cve-2026-73429</title>
    <updated>2026-10-05T23:59:23.839689+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Russh is a Rust SSH client &amp; server library. Prior to 0.62.4, a malicious SSH server can crash a russh client session with a malformed KEX_ECDH_REPLY containing a server ephemeral value that is not 32 bytes long. The client-side Curve25519Kex::compute_shared_secret function in russh/src/kex/curve25519.rs passes the decoded exchange.server_ephemeral value to clone_from_slice without validating its length, causing a deterministic panic before the server host key is verified. The panic terminates the spawned client session task and surfaces as a JoinError, while the embedding process normally remains running. This issue is fixed in version 0.62.4.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-73429"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-g9hv-x236-4qp3</id>
    <title>GHSA-g9hv-x236-4qp3 — Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS)</title>
    <updated>2026-10-05T23:59:23.839726+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: russh</p>
<p>### Summary
A malicious SSH server can crash a `russh` client session with a single
malformed key-exchange reply, causing a pre-authentication Denial-of-Service
before the server host key is verified. The embedding process itself stays
up, but the connection is killed deterministically.</p>
<p>### Details
Every *other* kex path in `russh` validates the peer ephemeral length before
cloning:</p>
<p>- `Curve25519Kex::server_dh` (`russh/src/kex/curve25519.rs:61-65`) checks
  `if pubkey_len != 32 { return Err(crate::Error::Kex); }` before
  `clone_from_slice`.
- The hybrid ML-KEM, ECDH-NIST, and DH/GEX paths all validate lengths.</p>
<p>Only the client-side curve25519 `compute_shared_secret` is missing the check.
This asymmetric validation gap makes the bug easy to miss in code review: a
malicious *client* cannot panic a `russh` server this way (the server path
checks the length), but a malicious *server* can panic a `russh` client.</p>
<p>Incriminated source code (repo-relative paths):</p>
<p>- Vulnerable `compute_shared_secret`: `russh/src/kex/curve25519.rs:110-117` (panic at line 113)
- Client-side entry point: `russh/src/client/kex.rs:266-277` (`KEX_ECDH_REPLY` → `Bytes::decode` → `compute_shared_secret`)
- Server-side contrast (has the length check): `russh/src/kex/curve25519.rs:51-88` (`server_dh`)
- Session spawn site: `russh/src/client/mod.rs` (`connect_stream` → `russh_util::runtime::spawn`)
- Runtime wrapper: `russh-util/src/runtime.rs:37-48` (`spawn` wraps `tokio::spawn`; panic surfaces as `JoinErr…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-g9hv-x236-4qp3"/>
  </entry>
</feed>
