Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-49295

Опубликовано: 10 янв. 2024
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

quic-go is an implementation of the QUIC protocol (RFC 9000, RFC 9001, RFC 9002) in Go. An attacker can cause its peer to run out of memory sending a large number of PATH_CHALLENGE frames. The receiver is supposed to respond to each PATH_CHALLENGE frame with a PATH_RESPONSE frame. The attacker can prevent the receiver from sending out (the vast majority of) these PATH_RESPONSE frames by collapsing the peers congestion window (by selectively acknowledging received packets) and by manipulating the peer's RTT estimate. This vulnerability has been patched in versions 0.37.7, 0.38.2 and 0.39.4.

A memory exhaustion vulnerability was found in Quic-GO, where a malicious client exploits the path validation mechanism to induce the server into accumulating an unbounded queue of PATH_RESPONSE frames, depleting its memory. The attacker controls the victim's packet send rate by overwhelming the server with numerous packets containing PATH_CHALLENGE frames. Through selective acknowledgments of received packets and manipulation of peer's Round-Trip Time (RTT) estimates, the attacker induces congestion control mechanisms to reduce the server's send rate significantly. Consequently, the victim server is compelled to store an increasing number of queued PATH_RESPONSE frames, resulting in memory exhaustion.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift API for Data Protectionoadp/oadp-velero-plugin-for-vsm-rhel8Not affected
OpenShift API for Data Protectionoadp/oadp-volume-snapshot-mover-rhel8Not affected
OpenShift Service Mesh 2openshift-service-mesh/istio-cni-rhel8Will not fix
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/lighthouse-agent-rhel9Affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/volsync-mover-rclone-rhel8Affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/volsync-mover-syncthing-rhel8Affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/volsync-rhel8Affected
Red Hat OpenShift Container Platform 4openshift4/ose-coredns-rhel9Affected
Red Hat OpenShift Dev Spacesdevspaces/traefik-rhel8Fix deferred
Red Hat Ansible Automation Platform 2.4 for RHEL 8receptorFixedRHSA-2024:085519.02.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2257815quic-go: memory exhaustion attack against QUIC's path validation mechanism

EPSS

Процентиль: 65%
0.01194
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.4
ubuntu
больше 2 лет назад

quic-go is an implementation of the QUIC protocol (RFC 9000, RFC 9001, RFC 9002) in Go. An attacker can cause its peer to run out of memory sending a large number of PATH_CHALLENGE frames. The receiver is supposed to respond to each PATH_CHALLENGE frame with a PATH_RESPONSE frame. The attacker can prevent the receiver from sending out (the vast majority of) these PATH_RESPONSE frames by collapsing the peers congestion window (by selectively acknowledging received packets) and by manipulating the peer's RTT estimate. This vulnerability has been patched in versions 0.37.7, 0.38.2 and 0.39.4.

CVSS3: 6.4
nvd
больше 2 лет назад

quic-go is an implementation of the QUIC protocol (RFC 9000, RFC 9001, RFC 9002) in Go. An attacker can cause its peer to run out of memory sending a large number of PATH_CHALLENGE frames. The receiver is supposed to respond to each PATH_CHALLENGE frame with a PATH_RESPONSE frame. The attacker can prevent the receiver from sending out (the vast majority of) these PATH_RESPONSE frames by collapsing the peers congestion window (by selectively acknowledging received packets) and by manipulating the peer's RTT estimate. This vulnerability has been patched in versions 0.37.7, 0.38.2 and 0.39.4.

CVSS3: 6.5
msrc
больше 2 лет назад

Описание отсутствует

CVSS3: 6.4
debian
больше 2 лет назад

quic-go is an implementation of the QUIC protocol (RFC 9000, RFC 9001, ...

CVSS3: 6.4
github
больше 2 лет назад

quic-go's path validation mechanism can be exploited to cause denial of service

EPSS

Процентиль: 65%
0.01194
Низкий

6.5 Medium

CVSS3