CVE-2023-39322 Information
Sep 10, 2023
cve
Description
QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages allowing a malicious QUIC connection to cause unbounded memory growth. With fix connections now consistently reject messages larger than 65KiB in size.
Reference
https://groups.google.com/g/golang-dev/c/2C5vbR-UNkI/m/L1hdrPhfBAAJ https://go.dev/cl/523039 https://go.dev/issue/62266 https://pkg.go.dev/vuln/GO-2023-2045
Share on: