<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 07:12:17 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-326594</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-326594</link>
      <description>EUVD-2026-326594</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-326594</guid>
    </item>
    <item>
      <title>fkie_cve-2026-48107</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48107</link>
      <description>&lt;p&gt;Russh is a Rust SSH client &amp;amp; server library. From version 0.37.0 to before version 0.61.0, in the russh client keyboard-interactive authentication path, a malicious SSH server could send a USERAUTH_INFO_REQUEST with an attacker-controlled prompt count, and the client would use that raw count directly in Vec::with_capacity(...) before validating that enough prompt data was actually present in the packet. This issue has been patched in version 0.61.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Russh is a Rust SSH client &amp;amp; server library. From version 0.37.0 to before version 0.61.0, in the russh client keyboard-interactive authentication path, a malicious SSH server could send a USERAUTH_INFO_REQUEST with an attacker-controlled prompt count, and the client would use that raw count directly in Vec::with_capacity(...) before validating that enough prompt data was actually present in the packet. This issue has been patched in version 0.61.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-48107</guid>
    </item>
    <item>
      <title>GHSA-g9g7-5cgw-6v28 — Russh: Unchecked keyboard-interactive prompt count in client auth path</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-g9g7-5cgw-6v28</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: russh&lt;/p&gt;
&lt;p&gt;### Summary
In the `russh` client keyboard-interactive authentication path, a malicious SSH server could send a `USERAUTH_INFO_REQUEST` with an attacker-controlled prompt count, and the client would use that raw count directly in `Vec::with_capacity(...)` before validating that enough prompt data was actually present in the packet.&lt;/p&gt;
&lt;p&gt;This is a client-side denial-of-service / resource-exhaustion issue on the keyboard-interactive auth path.&lt;/p&gt;
&lt;p&gt;### Details
The vulnerable code path is in:&lt;/p&gt;
&lt;p&gt;- `russh/src/client/encrypted.rs`&lt;/p&gt;
&lt;p&gt;When the client is in `CurrentRequest::KeyboardInteractive` state and receives `SSH_MSG_USERAUTH_INFO_REQUEST`, it parses:&lt;/p&gt;
&lt;p&gt;1. `name`
2. `instructions`
3. `language tag`
4. `n_prompts`&lt;/p&gt;
&lt;p&gt;Before the fix, the code then did:&lt;/p&gt;
&lt;p&gt;```rust
let n_prompts = map_err!(u32::decode(&amp;amp;mut r))?;
let mut prompts = Vec::with_capacity(n_prompts.try_into().unwrap_or(0));
```&lt;/p&gt;
&lt;p&gt;That means a malicious server could advertise an enormous `n_prompts` value even if the packet contained no prompt bodies at all.&lt;/p&gt;
&lt;p&gt;The fix rejects inconsistent prompt counts before allocating:&lt;/p&gt;
&lt;p&gt;```rust
let n_prompts = map_err!(u32::decode(&amp;amp;mut r))?;
let max_prompts = r.remaining_len() / 5;
let n_prompts = n_prompts as usize;
if n_prompts &amp;gt; max_prompts {
    return Err(crate::Error::Inconsistent.into());
}
let mut prompts = Vec::with_capacity(n_prompts);
```&lt;/p&gt;
&lt;p&gt;Each prompt needs at least 4 bytes of string length plus 1 byte of echo flag, so `remaining_len() / 5` is a safe upper bound. If the declared count exceeds w…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: russh&lt;/p&gt;
&lt;p&gt;### Summary
In the `russh` client keyboard-interactive authentication path, a malicious SSH server could send a `USERAUTH_INFO_REQUEST` with an attacker-controlled prompt count, and the client would use that raw count directly in `Vec::with_capacity(...)` before validating that enough prompt data was actually present in the packet.&lt;/p&gt;
&lt;p&gt;This is a client-side denial-of-service / resource-exhaustion issue on the keyboard-interactive auth path.&lt;/p&gt;
&lt;p&gt;### Details
The vulnerable code path is in:&lt;/p&gt;
&lt;p&gt;- `russh/src/client/encrypted.rs`&lt;/p&gt;
&lt;p&gt;When the client is in `CurrentRequest::KeyboardInteractive` state and receives `SSH_MSG_USERAUTH_INFO_REQUEST`, it parses:&lt;/p&gt;
&lt;p&gt;1. `name`
2. `instructions`
3. `language tag`
4. `n_prompts`&lt;/p&gt;
&lt;p&gt;Before the fix, the code then did:&lt;/p&gt;
&lt;p&gt;```rust
let n_prompts = map_err!(u32::decode(&amp;amp;mut r))?;
let mut prompts = Vec::with_capacity(n_prompts.try_into().unwrap_or(0));
```&lt;/p&gt;
&lt;p&gt;That means a malicious server could advertise an enormous `n_prompts` value even if the packet contained no prompt bodies at all.&lt;/p&gt;
&lt;p&gt;The fix rejects inconsistent prompt counts before allocating:&lt;/p&gt;
&lt;p&gt;```rust
let n_prompts = map_err!(u32::decode(&amp;amp;mut r))?;
let max_prompts = r.remaining_len() / 5;
let n_prompts = n_prompts as usize;
if n_prompts &amp;gt; max_prompts {
    return Err(crate::Error::Inconsistent.into());
}
let mut prompts = Vec::with_capacity(n_prompts);
```&lt;/p&gt;
&lt;p&gt;Each prompt needs at least 4 bytes of string length plus 1 byte of echo flag, so `remaining_len() / 5` is a safe upper bound. If the declared count exceeds w…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-g9g7-5cgw-6v28</guid>
    </item>
  </channel>
</rss>
