---
title: "CVE-2026-46673\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2026-46673?format=md
keywords: index, follow
---

# CVE-2026-46673

Publication date 10 June 2026

Last updated 19 June 2026

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Russh is a Rust SSH client & server library. Prior to version 0.60.3,
CryptoVec used unchecked capacity growth, unchecked length arithmetic, and
unsafe allocation/locking paths. In current russh releases, local SSH agent
peers could still feed attacker-controlled frame lengths into buffer growth
before validation. In older russh releases before 0.58.0, remote SSH
traffic also reached CryptoVec through transport and compression buffers.
This issue has been patched in version 0.60.3.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-46673)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2026-46673)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2026-46673)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2026-46673)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2026-46673>
* <https://github.com/Eugeny/russh/security/advisories/GHSA-g9f8-wqj9-fjw5>
