Improper Release of Memory Before Removing Last Reference ('Memory Leak') Affecting microsoft.native.quic.msquic.openssl package, versions [,2.2.3)
Threat Intelligence
EPSS
0.11% (46th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-DOTNET-MICROSOFTNATIVEQUICMSQUICOPENSSL-5960123
- published 11 Oct 2023
- disclosed 10 Oct 2023
- credit ziming zhang
Introduced: 10 Oct 2023
CVE-2023-36435 Open this link in a new tabHow to fix?
Upgrade Microsoft.Native.Quic.MsQuic.OpenSSL
to version 2.2.3 or higher.
Overview
Affected versions of this package are vulnerable to Improper Release of Memory Before Removing Last Reference ('Memory Leak') in the QUIC transport parameters when multiple instances are present or multiple calls to the decode happen.
An attacker can cause a denial of service when the MsQuic
server is in operation by continuously leaking memory until no more is available.
References
CVSS Scores
version 3.1