cve/2024/CVE-2024-32650.md
2024-06-18 02:51:15 +02:00

987 B

CVE-2024-32650

Description

Rustls is a modern TLS library written in Rust. rustls::ConnectionCommon::complete_io could fall into an infinite loop based on network input. When using a blocking rustls server, if a client send a close_notify message immediately after client_hello, the server's complete_io will get in an infinite loop. This vulnerability is fixed in 0.23.5, 0.22.4, and 0.21.11.

POC

Reference

Github

No PoCs found on GitHub currently.