Resource exhaustion via memory leak in tokio-boring
Published Dec 5, 2023
5.3
MEDIUMCVSS 3.1
EPSS 0.62%
Description
The tokio-boring library in version 4.0.0 is affected by a memory leak issue that can lead to excessive resource consumption and potential DoS by resource exhaustion. The set_ex_data function used by the library did not deallocate memory used by pre-existing data in memory each time after completing a TLS connection causing the program to consume more resources with each new connection.
Affected products
-
Affected
- ≥ 4.0.0, ≤ 4.1.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Cloudflare | Tokio-Boring | unaffected | Affected
|
- 4.0.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-3262 Advisory
- https://github.com/advisories/GHSA-pjrj-h4fg-6gm4 Advisory
- https://github.com/cloudflare/boring/commit/a32783374f2682e6949fdb713910b1b9f103d3ed
- https://github.com/cloudflare/boring/security/advisories/GHSA-pjrj-h4fg-6gm4 Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-6180
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
Red Hat
No data
GitHub