← back
CVE-2023-39322

Memory exhaustion in QUIC connection handling in crypto/tls

EPSS 1.1%
QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a malicious QUIC connection to cause unbounded memory growth. With fix, connections now consistently reject messages larger than 65KiB in size.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →