Back

HIGH

quic-go vulnerable to pointer dereference that can lead to panic

Published Oct 31, 2023

Description

quic-go is an implementation of the QUIC protocol in Go. Starting in version 0.37.0 and prior to version 0.37.3, by serializing an ACK frame after the CRYTPO that allows a node to complete the handshake, a remote node could trigger a nil pointer dereference (leading to a panic) when the node attempted to drop the Handshake packet number space. An attacker can bring down a quic-go node with very minimal effort. Completing the QUIC handshake only requires sending and receiving a few packets. Version 0.37.3 contains a patch. Versions before 0.37.0 are not affected.

Affected products

Remediation

No remediation recorded yet.

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Oct 31, 2023
Updated Sep 5, 2024
Reserved Oct 19, 2023
CISA Vulnrichment
Updated Sep 5, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner GitHub_M
Published Oct 31, 2023
Updated Sep 5, 2024
Exploited since n/a
EUVD-2023-2633 GHSA-3Q6M-V84F-6P9H