VDB
Sign up
MEDIUM

GHSA-hxq4-mx37-fqvg

s2n-quic potential denial of service vulnerability when receiving empty UDP packets

Details

### Impact

An issue in s2n-quic results in the endpoint shutting down after receiving an empty UDP packet on a connection.

No AWS services are affected by this issue and customers of AWS services do not need to take action. Applications using s2n-quic should upgrade their application to the most recent release of s2n-quic.

Impacted version: s2n-quic v1.22.0.

### Patches

The patch is included in s2n-quic [v1.23.0](https://github.com/aws/s2n-quic/releases/tag/v1.23.0).

If you have any questions or comments about this advisory we ask that you contact AWS/Amazon Security via our [vulnerability reporting page](https://aws.amazon.com/security/vulnerability-reporting) or directly via email to [aws-security@amazon.com](mailto:aws-security@amazon.com). Please do not create a public GitHub issue.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/s2n-quic
Introduced in: 1.22.0Fixed in: 1.23.0

Upgrade s2n-quic to 1.23.0 or newer (ecosystem crates.io).

References