CVE-2026-102825

Publication date 29 September 2026

Last updated 30 September 2026


Ubuntu priority

Cvss 3 Severity Score

3.7 · Low

Score breakdown

Description

Russh is a Rust SSH client and server library. Prior to 0.62.6, the USERAUTH_REQUEST path reached from server::run_stream in russh/src/server/encrypted.rs increments self.common.auth_attempts but never compares it with server::Config.max_auth_attempts. An unauthenticated remote client can continue submitting authentication requests on one connection beyond the configured cap, bypassing the deployment's attempt-limiting policy and increasing online guessing opportunity and backend authentication workload. This issue is fixed in version 0.62.6.

Status

Package Ubuntu Release Status
rust-russh 26.04 LTS resolute Not in release
24.04 LTS noble Not in release
22.04 LTS jammy Not in release

Severity score breakdown

CVSS version: CVSS v3.0

Base score 3.7 · Low

Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N


Access our resources on patching vulnerabilities