CVE Feed

    Dashboard / CVE / CVE-2024-43410

    CVE-2024-43410

    Russh is a Rust SSH client & server library. Allocating an untrusted amount of memory allows any unauthenticated user to OOM a russh server. An SSH packet consists of a 4-byte big-endian length, followed by a byte stream of this length. After parsing and potentially decrypting the 4-byte length, russh allocates enough memory for this bytestream, as a performance optimization to avoid reallocations later. But this length is entirely untrusted and can be set to any value by the client, causing this much memory to be allocated, which will cause the process to OOM within a few such requests. This vulnerability is fixed in 0.44.1.

    Published:Aug 21, 2024
    Last Modified:Aug 13, 2025
    EPS:Aug 21, 2024
    EPSS Score:0.00104
    CVSS Score:7.5

    Affected Products

    Vendor
    Russh Project
    Product
    Russh
    Vendor
    Warpgate Project
    Product
    Warpgate

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High