GHSA-cqjc-rmpq-xprq
## Summary A post-authentication denial-of-service panic in `russh` 0.62.2 (commit `c4be19f1915c8682f4615c3fd50008512b474491`, current default branch `main` as of 2026-07-22). An authenticated client sends a `pty-req` channel request carrying more than 130 terminal-mode records. The parser uses a fixed `[(Pty::TTY_OP_END, 0); 130]` array but increments its counter `i` for every valid record (logging "too many pty codes" without returning), then slices `&modes[0..i]` — an out-of-bounds slice that **panics** (`range end index 131 out of range for slice of length 130`) before the application `pty_request` handler runs. This is reachable with the **default** server configuration and the **default** crypto config (curve25519-sha256 + chacha20-poly1305), requiring only an authenticated session channel — no caller-supplied parameter. It is reproduced end-to-end against the unmodified real russh 0.62.2 library (a real `russh::client` + `russh::server` over TCP, using the public `Channel::request_pty(...)` API); the PoC below links the real crate, not a copied snippet. The defect is still present on `main` HEAD (`v0.62.3`, 2026-07-22) and is not covered by any of the 11 published russh GHSA advisories (GHSA-4r3c-5hpg-58qr / CVE-2026-48110 is allocation-first string parsing, not the fixed-array slice overflow; it was fixed in 0.61.0 but this code path still overflows the fixed array). Rust bounds-checked panics abort the task safely (no memory corruption / RCE); the impact is remote **denial of service**. ## Details `russh/src/server/encrypted.rs`, `pty-req` handling (lines 1137–1201): ```rust let mut modes = [(Pty::TTY_OP_END, 0); 130]; // fixed 130-entry array (line 1137) let mut i = 0; ... while !mode_bytes.is_empty() { let code = mode_bytes[0]; if code == 0 { if mode_bytes.len() != 1 { return Err(...); } break; } if mode_bytes.len() < 5 { return Err(...); } let num = BigEndian::read_u32(&mode_bytes[1..5]); if let Some(code) = Pty::from_u8(cod
Properties
- ghsa_id
- GHSA-cqjc-rmpq-xprq
- severity
- medium
- summary
- Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records
- cvss_score
- 4.3
- cve_id
- GHSA-cqjc-rmpq-xprq
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
- is_ghsa_only
- true
- ghsa_published
- 2026-07-24T16:46:13Z
- source_url
- https://github.com/advisories/GHSA-cqjc-rmpq-xprq
- ghsa_updated
- 2026-07-24T16:46:14Z
Related Entities (4)
REPORTED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
Explore deeper with Ninja Signal's threat intelligence graph