HIGH
Quicly assertion failures
Published Oct 11, 2024
7.5
HIGHCVSS 3.1
EPSS 0.58%
Description
Quicly is an IETF QUIC protocol implementation. Quicly up to commtit d720707 is susceptible to a denial-of-service attack. A remote attacker can exploit these bugs to trigger an assertion failure that crashes process using quicly. The vulnerability is addressed with commit 2a95896104901589c495bc41460262e64ffcad5c.
Affected products
-
Affected
- <
-
Affected
- ≥ 0, <
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| H2o Project | Quicly | unknown | Affected
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-41457 Advisory
- https://github.com/h2o/quicly/commit/2a95896104901589c495bc41460262e64ffcad5c x_refsource_MISCPatch
- https://github.com/h2o/quicly/security/advisories/GHSA-mp3c-h5gg-mm6p x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-41457 | Advisory | |
| https://github.com/h2o/quicly/commit/2a95896104901589c495bc41460262e64ffcad5c | x_refsource_MISCPatch | |
| https://github.com/h2o/quicly/security/advisories/GHSA-mp3c-h5gg-mm6p | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Oct 11, 2024
Updated Oct 15, 2024
Reserved Aug 28, 2024
Link CVE-2024-45396
CISA Vulnrichment
Updated Oct 11, 2024
Red Hat
No data
GitHub
No data