Skip to content

Potential denial of service when sending version negotiation or close packets

Moderate
camshaft published GHSA-gj4j-vp5f-86cf May 5, 2022

Package

cargo s2n-quic (Rust)

Affected versions

< v1.1.1

Patched versions

v1.1.1

Description

Some sender components could potentially panic when writing packets, leading to the endpoint shutting down.

AWS Services are not affected by this issue.

Customers using s2n-quic in their applications should update to the most recent version.

All versions of s2n-quic before and including v1.1.0 are affected by this issue. Customers should upgrade to v1.1.1.

Note that this issue does not affect s2n-tls.

Severity

Moderate

CVE ID

No known CVE

Weaknesses

No CWEs