Vulnerability record · CVE-2025-54804 · published 5 August 2025
CVE-2025-54804: Russh project russh integer overflow vulnerability
Russh Project · Russh
Russh is a Rust SSH client & server library. In versions 0.54.0 and below, the channel window adjust message of the SSH protocol is used to track the free space in the receive buffer of the other side of a channel. The current implementation takes the value from the message and adds it to an internal state value. This can result in a integer overflow. If the Rust code is compiled with overflow checks, it will panic. A malicious client can crash a server. This is fixed in version 0.54.1.
Description
Russh is a Rust SSH client & server library. In versions 0.54.0 and below, the channel window adjust message of the SSH protocol is used to track the free space in the receive buffer of the other side of a channel. The current implementation takes the value from the message and adds it to an internal state value. This can result in a integer overflow. If the Rust code is compiled with overflow checks, it will panic. A malicious client can crash a server. This is fixed in version 0.54.1.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/Eugeny/russh/commit/0eb5e406780890e21ff71dd25d731b30676478e5 | Patch |
| https://github.com/Eugeny/russh/security/advisories/GHSA-h5rc-j5f5-3gcm | ExploitVendor Advisory |
| https://github.com/Eugeny/russh/security/advisories/GHSA-h5rc-j5f5-3gcm | ExploitVendor Advisory |
Track CVE-2025-54804 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-54804), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.