天下漏洞,尽知其名
MEDIUM 重点关注

CVE-2026-102824 Russh 混合密钥交换降级漏洞

影响恶意 SSH 对端可削弱混合密钥交换的安全强度

AI 研判

Russh 是 Rust 语言的 SSH 客户端与服务器库。在 0.63.0 之前,其混合 ML-KEM 768 与 X25519 密钥交换实现会接受全零的 32 字节对端 X25519 公钥,使 X25519 对组合共享密钥的贡献被强制归零。攻击者借此可让组合密钥仅依赖 ML-KEM,破坏混合交换设计的回退保护。

影响范围

Russh

Russh 0.63.0 之前的版本,具体受影响版本范围暂无更细公开信息。

漏洞详情

漏洞属于密钥交换降级类问题。在 server_dh 与 compute_shared_secret 中未校验对端 X25519 公钥是否全零,导致 X25519 共享值恒为零,组合密钥退化为仅由 ML-KEM 决定。恶意 SSH 对端可利用该缺陷削弱混合交换的冗余保护。

利用条件与风险

利用前提是攻击者能作为 SSH 对端参与密钥协商,且需结合 ML-KEM 后续被削弱的假设,实战中单独利用风险有限,CVSS 评级为中等。

修复建议

升级至 Russh 0.63.0 或更高版本;暂无其他公开临时缓解措施信息。

原始情报

Russh is a Rust SSH client and server library. Prior to 0.63.0, the hybrid ML-KEM 768 and X25519 implementation in russh/src/kex/hybrid_mlkem.rs accepts an all-zero 32-byte peer X25519 public key in both server_dh and compute_shared_secret, forcing the X25519 contribution to the combined shared secret to zero. A malicious SSH peer can therefore make the combined secret depend only on ML-KEM, defeating the hybrid exchange’s intended fallback protection if ML-KEM is later weakened. This issue is fixed in version 0.63.0.