Impact
AsyncSSH accepts a zero send packet size from a peer, causing its internal loop to slice and remove zero bytes repeatedly without ever yielding control to the asyncio scheduler. The loop never completes, permanently blocking the event‑loop for that connection and any other coroutines scheduled thereafter. This results in a denial of service for the affected process.
Affected Systems
The affected item is the AsyncSSH Python library, maintained by ronf. All releases earlier than 2.24.0 are vulnerable. The patch to fix the issue is included in the 2.24.0 release and later.
Risk and Exploitability
The CVSS score is 6.5, categorising it as a moderate severity DoS. The EPSS score is below 1%, indicating a very low likelihood of exploitation, and the vulnerability is not yet listed in the CISA KEV catalog. The attack requires a malicious SSH server that sends a SSH_MSG_CHANNEL_OPEN_CONFIRMATION with a send packet size of zero, or an authenticated client that initiates a channel open with the same value. No privilege escalation or code execution is achieved; the threat is strictly availability.
OpenCVE Enrichment
Github GHSA