CVE-2024-1765 MEDIUM

CVE-2024-1765: Unlimited resource allocation by QUIC CRYPTO frames flooding in quiche

Vendor Cloudflare
Product quiche
Weakness CWE-400
Published March 12, 2024
Last update August 1, 2024

CVSS base score

5.9/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality None
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

What the vulnerability does

01Description

Cloudflare Quiche (through version 0.19.1/0.20.0) was affected by an unlimited resource allocation vulnerability causing rapid increase of memory usage of the system running quiche server or client. A remote attacker could take advantage of this vulnerability by repeatedly sending an unlimited number of 1-RTT CRYPTO frames after previously completing the QUIC handshake. Exploitation was possible for the duration of the connection which could be extended by the attacker.  quiche 0.19.2 and 0.20.1 are the earliest versions containing the fix for this issue.

Key dates

02Disclosure timeline

March 12, 2024 CVE published
August 1, 2024 Record updated