Impact
The vulnerability occurs in the pageant crate used by russh, specifically in the MemoryMap::read function of the WindowMessage module. It accepts an untrusted 32‑bit length supplied by a Pageant agent and trusts it completely. An attacker can supply a length near 4 GiB, causing the function to read beyond the 8,192‑byte shared‑memory view. The out‑of‑bounds read copies data from memory regions adjacent to or beyond the intended buffer, which can result in a crash of the russh client and accidental disclosure of sensitive data that resides next to the shared memory. The weakness aligns with CWE‑125 and CWE‑789.
Affected Systems
The flaw affects the russh project’s pageant crate (rust:pageant) developed by Eugeny. It applies to Windows installations that employ pageant versions earlier than 0.2.3. The issue was fixed in pageant 0.2.3 and newer releases.
Risk and Exploitability
This vulnerability has a CVSS score of 6.2, indicating moderate severity. An EPSS score is not available and the flaw has not been listed in CISA’s KEV catalog, implying limited observed exploitation. The problem requires a local process capable of impersonating the Pageant window class, so the attack vector is local with no remote component. A local attacker can trigger the buffer overflow, crash the russh client, and read adjacent memory. Overall, the risk is moderate but warrants timely remediation.
OpenCVE Enrichment