Answer in brief
CVE-2026-102820 records a Medium severity (CVSS 6.2) vulnerability in pageant: Out-of-bounds read / oversized allocation in `pageant` MemoryMap::read via a malicious Pageant agent (Windows). The current sources do not mark it as known exploited. The current feed maps rust/pageant (generic), Eugeny/russh (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 6.2. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps rust/pageant (generic), Eugeny/russh (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| rust/pageantgeneric | <0.2.3 | 0.2.3 |
| Eugeny/russhgeneric | <0.63.2 | 0.63.2 |
Published upstream
Sep 29, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 29, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 29, 2026
pageant provides a [PageantStream] type that implements [AsyncRead] and [AsyncWrite] traits and can be used to talk to a running Pageant instance. Prior to pageant 0.2.3, the Windows pageant crate's pageant/src/wmmessage.rs MemoryMap::read function trusts a peer-controlled u32 response length supplied through the 8192-byte Pageant shared-memory mapping reached by AgentClient::connect_pageant. A local process that impersonates the Pageant window can make query_pageant_direct allocate up to approximately 4 GiB and copy beyond the mapped view, reliably crashing a russh client and conditionally exposing adjacent committed memory. This issue is fixed in pageant 0.2.3.
Quoted source text, attributed separately from HOL analysis.