Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS03OHd4LWpnNGotNWo2Z84AA586

quiche vulnerable to unlimited resource allocation by QUIC CRYPTO frames flooding

Impact

Cloudflare Quiche (through version 0.19.1/0.20.0) was affected by an unlimited resource allocation vulnerability causing rapid increase of memory usage of the system running quiche server or client.

A remote attacker could take advantage of this vulnerability by repeatedly sending an unlimited number of 1-RTT CRYPTO frames after previously completing the QUIC handshake.
Exploitation was possible for the duration of the connection which could be extended by the attacker.

Patches

Quiche 0.19.2 and 0.20.1 are the earliest versions containing the fix for this issue.

Permalink: https://github.com/advisories/GHSA-78wx-jg4j-5j6g
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03OHd4LWpnNGotNWo2Z84AA586
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: about 1 month ago
Updated: about 1 month ago


CVSS Score: 5.9
CVSS vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Identifiers: GHSA-78wx-jg4j-5j6g, CVE-2024-1765
References: Repository: https://github.com/cloudflare/quiche
Blast Radius: 4.6

Affected Packages

cargo:quiche
Dependent packages: 4
Dependent repositories: 6
Downloads: 239,624 total
Affected Version Ranges: >= 0.20.0, < 0.20.1, < 0.19.2
Fixed in: 0.20.1, 0.19.2
All affected versions: 0.1.0, 0.2.0, 0.3.0, 0.4.0, 0.5.0, 0.5.1, 0.6.0, 0.7.0, 0.8.0, 0.8.1, 0.9.0, 0.10.0, 0.11.0, 0.12.0, 0.13.0, 0.14.0, 0.15.0, 0.16.0, 0.17.0, 0.17.1, 0.17.2, 0.18.0, 0.19.0, 0.19.1, 0.20.0
All unaffected versions: 0.19.2, 0.20.1