Description
AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Prior to 2.24.0, _process_channel_open and _process_channel_open_confirmation in asyncssh/connection.py accept a peer-supplied send_pktsize value of zero. When channel data reaches SSHChannel._flush_send_buf in asyncssh/channel.py, the zero value causes each loop iteration to slice and remove zero bytes without reducing the send window, leaving the synchronous loop permanently true with no await point. A malicious SSH server can trigger the client path through SSH_MSG_CHANNEL_OPEN_CONFIRMATION before the first channel write, while an authenticated client can trigger the server path through SSH_MSG_CHANNEL_OPEN and freeze every current and future connection handled by the process. This vulnerability is fixed in 2.24.0.
Published: 2026-09-16
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Now
AI Analysis

Impact

AsyncSSH accepts a zero send packet size from a peer, causing its internal loop to slice and remove zero bytes repeatedly without ever yielding control to the asyncio scheduler. The loop never completes, permanently blocking the event‑loop for that connection and any other coroutines scheduled thereafter. This results in a denial of service for the affected process.

Affected Systems

The affected item is the AsyncSSH Python library, maintained by ronf. All releases earlier than 2.24.0 are vulnerable. The patch to fix the issue is included in the 2.24.0 release and later.

Risk and Exploitability

The CVSS score is 6.5, categorising it as a moderate severity DoS. The EPSS score is below 1%, indicating a very low likelihood of exploitation, and the vulnerability is not yet listed in the CISA KEV catalog. The attack requires a malicious SSH server that sends a SSH_MSG_CHANNEL_OPEN_CONFIRMATION with a send packet size of zero, or an authenticated client that initiates a channel open with the same value. No privilege escalation or code execution is achieved; the threat is strictly availability.

Generated by OpenCVE AI on September 17, 2026 at 21:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade AsyncSSH to v2.24.0 or later.
  • If an upgrade cannot be performed immediately, restrict SSH traffic to trusted hosts and limit use of the vulnerable library to essential connections only.
  • Implement a watchdog or restart mechanism to recover from potential event‑loop freezes, and monitor for abnormal CPU usage or lack of task scheduling.

Generated by OpenCVE AI on September 17, 2026 at 21:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-rw4j-r22c-9gc3 AsyncSSH: asyncio event-loop freeze via SSH maximum packet size = 0 in SSH_MSG_CHANNEL_OPEN / OPEN_CONFIRMATION
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Ronf
Ronf asyncssh
Vendors & Products Ronf
Ronf asyncssh

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 16 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Prior to 2.24.0, _process_channel_open and _process_channel_open_confirmation in asyncssh/connection.py accept a peer-supplied send_pktsize value of zero. When channel data reaches SSHChannel._flush_send_buf in asyncssh/channel.py, the zero value causes each loop iteration to slice and remove zero bytes without reducing the send window, leaving the synchronous loop permanently true with no await point. A malicious SSH server can trigger the client path through SSH_MSG_CHANNEL_OPEN_CONFIRMATION before the first channel write, while an authenticated client can trigger the server path through SSH_MSG_CHANNEL_OPEN and freeze every current and future connection handled by the process. This vulnerability is fixed in 2.24.0.
Title AsyncSSH: asyncio event-loop freeze via SSH maximum packet size = 0 in SSH_MSG_CHANNEL_OPEN / OPEN_CONFIRMATION
Weaknesses CWE-835
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T15:01:48.863Z

Reserved: 2026-07-14T22:32:17.731Z

Link: CVE-2026-62949

cve-icon Vulnrichment

Updated: 2026-09-17T15:01:45.695Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T20:17:26.220

Modified: 2026-09-30T17:43:24.057

Link: CVE-2026-62949

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-16T20:00:46Z

Links: CVE-2026-62949 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:45:16Z

Weaknesses
  • CWE-835

    Loop with Unreachable Exit Condition ('Infinite Loop')