VDB
Sign up
MEDIUM5.9

GHSA-78wx-jg4j-5j6g

quiche vulnerable to unlimited resource allocation by QUIC CRYPTO frames flooding

Details

### Impact

Cloudflare Quiche (through version 0.19.1/0.20.0) was affected by an unlimited resource allocation vulnerability causing rapid increase of memory usage of the system running quiche server or client.

A remote attacker could take advantage of this vulnerability by repeatedly sending an unlimited number of 1-RTT CRYPTO frames after previously completing the QUIC handshake. Exploitation was possible for the duration of the connection which could be extended by the attacker.

### Patches

Quiche 0.19.2 and 0.20.1 are the earliest versions containing the fix for this issue.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/quiche
Introduced in: 0Fixed in: 0.19.2

Upgrade quiche to 0.19.2 or newer (ecosystem crates.io).

crates.io/quiche
Introduced in: 0.20.0Fixed in: 0.20.1

Upgrade quiche to 0.20.1 or newer (ecosystem crates.io).

References