PT-2025-7548 · Picoquic · Picoquic

Ncc-Pbottine

·

Published

2025-02-20

·

Updated

2025-02-20

·

CVE-2025-24946

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions picoquic versions before b80fd3f
Description The hash table used to manage connections in picoquic uses a weak hash function, allowing remote attackers to cause a considerable CPU load on the server by initiating connections with colliding Source Connection IDs (SCIDs), resulting in a Hash DoS attack.
Recommendations For picoquic versions before b80fd3f, update to a version after b80fd3f to resolve the issue. As a temporary workaround, consider implementing measures to detect and prevent connections with colliding Source Connection IDs (SCIDs) to minimize the risk of exploitation.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-24946

Affected Products

Picoquic