[GO-2023-2045] Memory exhaustion in QUIC connection handling in crypto/tls

Severity High
Affected Packages 1
Fixed Packages 1
CVEs 1

QUIC connections do not set an upper bound on the amount of data buffered when
reading post-handshake messages, allowing a malicious QUIC connection to cause
unbounded memory growth.

With fix, connections now consistently reject messages larger than 65KiB in

Package Affected Version
pkg:golang/crypto/tls >= 1.21.0, < 1.21.1
Package Fixed Version
pkg:golang/crypto/tls = 1.21.1
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Fixed pkg:golang/crypto/tls crypto tls = 1.21.1
Affected pkg:golang/crypto/tls crypto tls >= 1.21.0 < 1.21.1
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date