GHSA-78wx-jg4j-5j6g
quiche vulnerable to unlimited resource allocation by QUIC CRYPTO frames flooding
Details
### Impact
Cloudflare Quiche (through version 0.19.1/0.20.0) was affected by an unlimited resource allocation vulnerability causing rapid increase of memory usage of the system running quiche server or client.
A remote attacker could take advantage of this vulnerability by repeatedly sending an unlimited number of 1-RTT CRYPTO frames after previously completing the QUIC handshake. Exploitation was possible for the duration of the connection which could be extended by the attacker.
### Patches
Quiche 0.19.2 and 0.20.1 are the earliest versions containing the fix for this issue.
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 0.19.2Upgrade quiche to 0.19.2 or newer (ecosystem crates.io).
0.20.0Fixed in: 0.20.1Upgrade quiche to 0.20.1 or newer (ecosystem crates.io).
References
- https://github.com/cloudflare/quiche/security/advisories/GHSA-78wx-jg4j-5j6g[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2024-1765[ADVISORY]
- https://github.com/cloudflare/quiche/commit/1017466c143fc93a82b286a1ba35e53334cdf8e2[WEB]
- https://github.com/cloudflare/quiche/commit/11dbf5461ab657bbc02e466d719070124b27ef3c[WEB]
- https://github.com/cloudflare/quiche[PACKAGE]
- https://github.com/cloudflare/quiche/releases/tag/0.19.2[WEB]
- https://github.com/cloudflare/quiche/releases/tag/0.20.1[WEB]