PT-2025-7544 · Kwik · Kwik

Ncc-Pbottine

·

Published

2025-02-20

·

Updated

2025-02-20

·

CVE-2025-23020

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Kwik versions prior to 0.10.1
Description A hash collision vulnerability in the hash table used to manage connections allows remote attackers to cause a considerable CPU load on the server by initiating connections with colliding Source Connection IDs (SCIDs). This results in a Hash DoS attack.
Recommendations For versions prior to 0.10.1, update to version 0.10.1 or later to resolve the issue. As a temporary workaround, consider implementing measures to limit the impact of excessive connection requests on the server, such as rate limiting or IP blocking, until a patch is applied.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-23020
GHSA-9F57-9RHG-4HVM

Affected Products

Kwik