PT-2025-23490 · Quic-Go+1 · Quic-Go+1

Marten-Seemann

·

Published

2025-06-02

·

Updated

2025-07-03

·

CVE-2025-29785

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions quic-go versions 0.50.0
Description The loss recovery logic for path probe packets in quic-go can be exploited by a malicious QUIC client to trigger a nil-pointer dereference. This is achieved by sending valid QUIC packets from different remote addresses, triggering the path validation logic and causing the server to send path probe packets, followed by sending specifically crafted ACKs for packets received from the server.
Recommendations For quic-go version 0.50.0, update to version 0.50.1, which contains a patch that fixes the vulnerability.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-29785
GHSA-J972-J939-P2V3
GO-2025-3735
OPENSUSE-SU-2025:15225-1

Affected Products

Debian
Quic-Go