PT-2024-13721 · Quic-Go+1 · Quic-Go+1

Marten-Seemann

·

Published

2024-01-10

·

Updated

2025-12-11

·

CVE-2023-49295

CVSS v3.1

6.4

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions quic-go versions prior to 0.37.7 quic-go versions prior to 0.38.2 quic-go versions prior to 0.39.4
Description An attacker can cause its peer to run out of memory by sending a large number of PATH CHALLENGE frames. The receiver is supposed to respond to each PATH CHALLENGE frame with a PATH RESPONSE frame. However, the attacker can prevent the receiver from sending out most of these PATH RESPONSE frames by collapsing the peer's congestion window and manipulating the peer's RTT estimate.
Recommendations For versions prior to 0.37.7, update to version 0.37.7 or later. For versions prior to 0.38.2, update to version 0.38.2 or later. For versions prior to 0.39.4, update to version 0.39.4 or later.

Exploit

Fix

Resource Exhaustion

Weakness Enumeration

Related Identifiers

AZL-33285
AZL-34627
CVE-2023-49295
GHSA-PPXX-5M9H-6VXF
GO-2024-2459
OPENSUSE-SU-2024:13570-1
OPENSUSE-SU-2025:14626-1
RHSA-2024:0855

Affected Products

Debian
Quic-Go