PT-2024-17221 · Rustls · Rustls

Kvinwang

·

Published

2024-11-22

·

Updated

2026-04-15

·

CVE-2024-11738

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Rustls version 0.23.13
Description A flaw was found in Rustls and related APIs, allowing denial of service (panic) via a fragmented TLS ClientHello message.
Recommendations For Rustls version 0.23.13, consider disabling the handling of fragmented TLS ClientHello messages as a temporary workaround until a patch is available.

Fix

DoS

Weakness Enumeration

Related Identifiers

AZL-61546
CVE-2024-11738
GHSA-QG5G-GV98-5FFH
OPENSUSE-SU-2024:14539-1
RUSTSEC-2024-0399
SUSE-SU-2026:1361-1

Affected Products

Rustls