Improper resource allocation In microsoft.native.quic.msquic.schannel
Description
Remote Denial of Service Vulnerability in Microsoft QUIC
Impact
The MsQuic server will continue to leak memory until no more is available, resulting in a denial of service.
Patches
The following patch was made:
Fix Memory Leak from Multiple Decodes of TP - https://github.com/microsoft/msquic/commit/5d070d661c45979946615289e92bb6b822efe9e9
Workarounds
Beyond upgrading to the patched versions, there is no other workaround.
MSRC CVE Info
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26190
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
nuget | 2.2.7, 2.3.5, 2.1.12 | ||
nuget | 2.1.12, 2.2.7, 2.3.5 |
Aliases
1. 2.
References
1. 2. 3. 4.