VDB
KO
MEDIUM 5.3

GHSA-9q54-f358-3fqf

s2n-quic has excessive memory allocation

Details

s2n-quic is a Rust implementation of the QUIC protocol. An unauthenticated user can attempt to exhaust server memory on an s2n-quic endpoint by sending crafted CRYPTO frames with high offsets. The buffer used for processing CRYPTO frames does not enforce a maximum size. In the worst case, a single 1200-byte packet can cause approximately 9.4 MB of allocation. By repeatedly sending such packets, the resulting memory pressure could cause denial of service. No valid handshake is required.

Impacted versions: <= v1.81.0

### Patches This issue has been addressed in s2n-quic version v1.82.0. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. 

### Workarounds There is no workaround that fully mitigates this issue. Upgrading to the patched version is the recommended remediation.

### References If there are any questions or comments about this advisory, contact AWS Security via the [vulnerability reporting page](https://aws.amazon.com/security/vulnerability-reporting) or directly via email to [aws-security@amazon.com](mailto:aws-security@amazon.com). Please do not create a public GitHub issue.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io / s2n-quic
Introduced in: 0 Fixed in: 1.82.0

Upgrade s2n-quic to 1.82.0 or newer (ecosystem crates.io).

References