Description
Processing an incomplete post-handshake message for a QUIC connection can cause a panic.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6Attack Vector: Network
Complexity: Low
Privileges: None
User Interaction: None
Scope: Unchanged
Confidentiality: None
Integrity: None
Availability: High
Affected Packages2 packages
🔴Vulnerability Details
4GHSAGHSA-9v7r-x7cv-v437: Processing an incomplete post-handshake message for a QUIC connection can cause a panic↗2023-09-08 ▶ CVEListPanic when processing post-handshake message on QUIC connections in crypto/tls↗2023-09-08 ▶ OSVCVE-2023-39321: Processing an incomplete post-handshake message for a QUIC connection can cause a panic↗2023-09-08 ▶ OSVPanic when processing post-handshake message on QUIC connections in crypto/tls↗2023-09-07 ▶ 📋Vendor Advisories
1Red Hatgolang: crypto/tls: panic when processing post-handshake message on QUIC connections↗2023-09-06 ▶