PT-2025-23490 · Quic-Go+1 · Quic-Go+1
Marten-Seemann
·
Published
2025-06-02
·
Updated
2025-07-03
·
CVE-2025-29785
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
quic-go versions 0.50.0
Description
The loss recovery logic for path probe packets in quic-go can be exploited by a malicious QUIC client to trigger a nil-pointer dereference. This is achieved by sending valid QUIC packets from different remote addresses, triggering the path validation logic and causing the server to send path probe packets, followed by sending specifically crafted ACKs for packets received from the server.
Recommendations
For quic-go version 0.50.0, update to version 0.50.1, which contains a patch that fixes the vulnerability.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Quic-Go