Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-2x7m-gf85-3745: Remote Denial of Service Vulnerability in Microsoft QUIC

Impact

The MsQuic server will continue to leak memory until no more is available, resulting in a denial of service.

Patches

The following patch was made:

  • Fix Memory Leak from Multiple Decodes of TP - https://github.com/microsoft/msquic/commit/5d070d661c45979946615289e92bb6b822efe9e9

Workarounds

Beyond upgrading to the patched versions, there is no other workaround.

MSRC CVE Info

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26190

ghsa
#vulnerability#microsoft#dos#git#ssl

Skip to content

    • Actions

      Automate any workflow

    • Packages

      Host and manage packages

    • Security

      Find and fix vulnerabilities

    • Codespaces

      Instant dev environments

    • Copilot

      Write better code with AI

    • Code review

      Manage code changes

    • Issues

      Plan and track work

    • Discussions

      Collaborate outside of code

    • GitHub Sponsors

      Fund open source developers

*   The ReadME Project
    
    GitHub community articles
  • Pricing

Provide feedback

Saved searches****Use saved searches to filter your results more quickly

Sign up

  1. GitHub Advisory Database
  2. GitHub Reviewed
  3. GHSA-2x7m-gf85-3745

Remote Denial of Service Vulnerability in Microsoft QUIC

High severity GitHub Reviewed Published Mar 12, 2024 in microsoft/msquic • Updated Mar 13, 2024

Package

nuget Microsoft.Native.Quic.MsQuic.OpenSSL (NuGet)

Affected versions

< 2.1.12

>= 2.2.0, < 2.2.7

>= 2.3.0, < 2.3.5

Patched versions

2.1.12

2.2.7

2.3.5

nuget Microsoft.Native.Quic.MsQuic.Schannel (NuGet)

>= 2.2.0, < 2.2.7

>= 2.3.0, < 2.3.5

< 2.1.12

Description

Published to the GitHub Advisory Database

Mar 13, 2024

Last updated

Mar 13, 2024

ghsa: Latest News

GHSA-4gfw-wf7c-w6g2: Authd allows attacker-controlled usernames to yield controllable UIDs