PT-2023-33059 · Amazon · S2N-Quic
Published
2023-07-24
·
Updated
2023-07-24
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
s2n-quic versions <=v1.24.0
Description
The issue in s2n-quic causes the endpoint to shut down due to a combination of peer-initiated connection migration and duplicate new connection ID frames being received. No AWS services are affected, and customers of AWS services do not need to take action.
Recommendations
For s2n-quic versions <=v1.24.0, upgrade the application to the most recent release of s2n-quic, specifically to version v1.25.0 or later, as it includes the patch for this issue.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
S2N-Quic