Improper resource allocation In stdlib
Description
A flaw was found in Golang. QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a malicious QUIC connection to cause unbounded memory growth. With the fix, connections now consistently reject messages larger than 65KiB in size.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
go | 1.21.1 | ||
rpm rhel9 | 1:1.31.3-2.el9_3 | ||
rpm rhel9 | 2:4.6.1-7.el9_3 | ||
rpm rhel9 | - | - | |
rpm rhel9 | - | - | |
rpm rhel9 | - | - | |
rpm rhel9 | 1:1.3.0-6.el9_3 | ||
rpm rhel8 | - | - | |
rpm rhel9 | 0:3.6.1-1.el9 | ||
rpm rhel8 | 0:1.20.10-1.module+el8.9.0+20382+04f7fe80 |
1-10 of 16
10
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3.