GHSA-hxq4-mx37-fqvg
s2n-quic potential denial of service vulnerability when receiving empty UDP packets
Details
### Impact
An issue in s2n-quic results in the endpoint shutting down after receiving an empty UDP packet on a connection.
No AWS services are affected by this issue and customers of AWS services do not need to take action. Applications using s2n-quic should upgrade their application to the most recent release of s2n-quic.
Impacted version: s2n-quic v1.22.0.
### Patches
The patch is included in s2n-quic [v1.23.0](https://github.com/aws/s2n-quic/releases/tag/v1.23.0).
If you have any questions or comments about this advisory we ask that you contact AWS/Amazon Security via our [vulnerability reporting page](https://aws.amazon.com/security/vulnerability-reporting) or directly via email to [aws-security@amazon.com](mailto:aws-security@amazon.com). Please do not create a public GitHub issue.
Are you affected?
Enter the version of the package you're using.
Affected packages
1.22.0Fixed in: 1.23.0Upgrade s2n-quic to 1.23.0 or newer (ecosystem crates.io).