PT-2023-29922 · Quic-Go · Quic-Go

Marten-Seemann

·

Publicado

2023-10-30

·

Atualizado

2023-11-09

·

CVE-2023-46239

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions quic-go versions 0.37.0 through 0.37.2
Description The issue arises from serializing an ACK frame after the CRYPTO frame, allowing a node to complete the handshake. This can trigger a nil pointer dereference when the node attempts to drop the Handshake packet number space, leading to a panic. An attacker can bring down a quic-go node with minimal effort by completing the QUIC handshake, which requires sending and receiving only a few packets.
Recommendations For quic-go versions 0.37.0 through 0.37.2, update to version 0.37.3 to resolve the issue. As a temporary workaround, consider restricting access to the QUIC handshake protocol until the patch is applied.

Exploit

Correção

NULL Pointer Dereference

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-46239
GHSA-3Q6M-V84F-6P9H
GO-2023-2160

Produtos afetados

Quic-Go