CVE Published: 08/09/2023 |
CVE Updated: 26/09/2024 |
CVE Year: 2023 Source: Go |
Vendor: Go standard library |
Product: crypto/tls Status : PUBLISHED
CVE-2023-39322 Description
QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a malicious QUIC connection to cause unbounded memory growth. With fix, connections now consistently reject messages larger than 65KiB in size.