quic-go is an implementation of the QUIC protocol in Go. Prior to version 0.42.0, an attacker can cause its peer to run out of memory sending a large number of `NEW_CONNECTION_ID` frames that retire old connection IDs. The receiver is supposed to respond to each retirement frame with a `RETIRE_CONNECTION_ID` frame. The attacker can prevent the receiver from sending out (the vast majority of) these `RETIRE_CONNECTION_ID` frames by collapsing the peers congestion window (by selectively acknowledging received packets) and by manipulating the peer's RTT estimate. Version 0.42.0 contains a patch for the issue. No known workarounds are available.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade kubo | Aug 22, 2024 | Apr 4, 2024 |
| Debian | — | Upgrade golang-github-lucas-clemente-quic-go | May 15, 2025 | Apr 4, 2024 |
| Suse | — | Upgrade golang-github-v2fly-v2ray-coreUpgrade caddyUpgrade corednsUpgrade coredns-extrasUpgrade caddy-fish-completionUpgrade caddy-zsh-completionUpgrade kuboUpgrade caddy-bash-completionUpgrade v2ray-core | Jul 23, 2024 | Apr 4, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub