---
id: CVE-2026-102820
title: >-
  pageant provides a [PageantStream] type that implements [AsyncRead] and
  [AsyncWrite] traits and can be used to talk to a running Pageant instance
summary: >-
  pageant provides a [PageantStream] type that implements [AsyncRead] and
  [AsyncWrite] traits and can be used to talk to a running Pageant instance.
  Prior to pageant 0.2.3, the Windows pageant crate's pageant/src/wmmessage.rs
  MemoryMap::re…
severity: medium
cvss: 6.2
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-125
  - CWE-789
vendor: Eugeny
product: russh
affected:
  - russh < 0.63.2
  - pageant < 0.2.3
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T19:17:23.820'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102820'
references:
  - url: >-
      https://github.com/Eugeny/russh/commit/5d566989ebabfdebfe6b33243d31765a0812260b
    label: security-advisories@github.com
  - url: 'https://github.com/Eugeny/russh/releases/tag/v0.63.2'
    label: security-advisories@github.com
  - url: 'https://github.com/Eugeny/russh/security/advisories/GHSA-g4mp-vgx3-xrvm'
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-29T18:42:35.836Z'
---

## Overview

pageant provides a [PageantStream] type that implements [AsyncRead] and [AsyncWrite] traits and can be used to talk to a running Pageant instance. Prior to pageant 0.2.3, the Windows pageant crate's pageant/src/wmmessage.rs MemoryMap::read function trusts a peer-controlled u32 response length supplied through the 8192-byte Pageant shared-memory mapping reached by AgentClient::connect_pageant. A local process that impersonates the Pageant window can make query_pageant_direct allocate up to approximately 4 GiB and copy beyond the mapped view, reliably crashing a russh client and conditionally exposing adjacent committed memory. This issue is fixed in pageant 0.2.3.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
