CVE-2026-102824 Russh 混合密钥交换降级漏洞
影响恶意 SSH 对端可削弱混合密钥交换的安全强度
Russh 是 Rust 语言的 SSH 客户端与服务器库。在 0.63.0 之前,其混合 ML-KEM 768 与 X25519 密钥交换实现会接受全零的 32 字节对端 X25519 公钥,使 X25519 对组合共享密钥的贡献被强制归零。攻击者借此可让组合密钥仅依赖 ML-KEM,破坏混合交换设计的回退保护。
影响范围
Russh 0.63.0 之前的版本,具体受影响版本范围暂无更细公开信息。
漏洞详情
漏洞属于密钥交换降级类问题。在 server_dh 与 compute_shared_secret 中未校验对端 X25519 公钥是否全零,导致 X25519 共享值恒为零,组合密钥退化为仅由 ML-KEM 决定。恶意 SSH 对端可利用该缺陷削弱混合交换的冗余保护。
利用条件与风险
利用前提是攻击者能作为 SSH 对端参与密钥协商,且需结合 ML-KEM 后续被削弱的假设,实战中单独利用风险有限,CVSS 评级为中等。
修复建议
升级至 Russh 0.63.0 或更高版本;暂无其他公开临时缓解措施信息。
Russh is a Rust SSH client and server library. Prior to 0.63.0, the hybrid ML-KEM 768 and X25519 implementation in russh/src/kex/hybrid_mlkem.rs accepts an all-zero 32-byte peer X25519 public key in both server_dh and compute_shared_secret, forcing the X25519 contribution to the combined shared secret to zero. A malicious SSH peer can therefore make the combined secret depend only on ML-KEM, defeating the hybrid exchange’s intended fallback protection if ML-KEM is later weakened. This issue is fixed in version 0.63.0.