Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-39322
HistorySep 08, 2023 - 5:15 p.m.

Design/Logic Flaw

2023-09-0817:15:00
PRIOn knowledge base
www.prio-n.com
9
quic
logic flaw
fix
memory growth
large messages

7.2 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

37.8%

QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a malicious QUIC connection to cause unbounded memory growth. With fix, connections now consistently reject messages larger than 65KiB in size.

CPENameOperatorVersion
goge1.21.0
golt1.21.1