Количество 2
Количество 2
CVE-2023-6180
The tokio-boring library in version 4.0.0 is affected by a memory leak issue that can lead to excessive resource consumption and potential DoS by resource exhaustion. The set_ex_data function used by the library did not deallocate memory used by pre-existing data in memory each time after completing a TLS connection causing the program to consume more resources with each new connection.
GHSA-pjrj-h4fg-6gm4
tokio-boring vulnerable to resource exhaustion via memory leak
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2023-6180 The tokio-boring library in version 4.0.0 is affected by a memory leak issue that can lead to excessive resource consumption and potential DoS by resource exhaustion. The set_ex_data function used by the library did not deallocate memory used by pre-existing data in memory each time after completing a TLS connection causing the program to consume more resources with each new connection. | CVSS3: 5.3 | 0% Низкий | около 2 лет назад | |
GHSA-pjrj-h4fg-6gm4 tokio-boring vulnerable to resource exhaustion via memory leak | CVSS3: 5.3 | 0% Низкий | около 2 лет назад |
Уязвимостей на страницу