Impact
The vulnerability allows an authenticated remote peer to send an SSH_MSG_KEXINIT message without the required SSH_MSG_KEX_ECDH_INIT, followed by a flood of SSH_MSG_CHANNEL_OPEN requests. Because the server's SessionKexState::InProgress state blocks priority_receiver from draining, the server enqueues a ChannelOpenReply for each request onto an unbounded channel, causing unbounded memory growth. This leads to a denial‑of‑service condition when the process eventually terminates due to exhaustion.
Affected Systems
The affected product is the russh library provided by Eugeny. Any release prior to 0.63.2 is vulnerable. After version 0.63.2 the issue has been fixed. Systems using an older russh version as a client or server library are at risk.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. No EPSS data was reported, and the vulnerability is not listed in CISA's KEV database. The attacker must already be authenticated with the target SSH service, so an adversary with valid credentials can trigger the denial-of-service by flooding channel open requests. Because the fault relies on an authenticated session, widespread exploitation is less likely, but environments that accept many connections from untrusted peers remain at risk.
OpenCVE Enrichment