Описание
Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls
Обновления
| Продукт | Статья | Обновление |
|---|---|---|
| azl3 golang 1.27.0-1 on Azure Linux 3.0 | ||
| azl3 golang 1.27.1-1 on Azure Linux 3.0 |
Показывать по
EPSS
7.5 High
CVSS3
Связанные уязвимости
If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.
If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.
If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.
If one side of the TLS connection sends multiple key update messages p ...
EPSS
7.5 High
CVSS3