PT-2022-20194 · Quic-Go+1 · Quic-Go+1
Published
2022-07-06
·
Updated
2024-08-03
·
CVE-2022-30591
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
quic-go versions through 0.27.0
Description
The issue allows remote attackers to cause a denial of service (CPU consumption) via a Slowloris variant in which incomplete QUIC or HTTP/3 requests are sent. This occurs because mtu discoverer.go misparses the MTU Discovery service and consequently overflows the probe timer.
Recommendations
For quic-go versions through 0.27.0, consider disabling the
mtu discoverer.go service until a patch is available to prevent the denial of service attack.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Quic-Go