CVE-2024-32650 Information
Apr 21, 2024
cve
Description
Rustls is a modern TLS library written in Rust. rustls::ConnectionCommon::complete_io could fall into an infinite loop based on network input. When using a blocking rustls server if a client send a close_notify message immediately after client_hello the server’s complete_io will get in an infinite loop. This vulnerability is fixed in 0.23.5 0.22.4 and 0.21.11.
Reference
https://github.com/rustls/rustls/security/advisories/GHSA-6g7w-8wpp-frhj https://github.com/rustls/rustls/commit/2123576840aa31043a31b0770e6572136fbe0c2d https://github.com/rustls/rustls/commit/6e938bcfe82a9da7a2e1cbf10b928c7eca26426e https://github.com/rustls/rustls/commit/f45664fbded03d833dffd806503d3c8becd1b71e
Share on: