Improper Release of Memory Before Removing Last Reference ('Memory Leak') Affecting microsoft.native.quic.msquic.schannel package, versions [,2.2.3)


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team

    Threat Intelligence

    EPSS
    0.11% (46th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk ID SNYK-DOTNET-MICROSOFTNATIVEQUICMSQUICSCHANNEL-5960122
  • published 11 Oct 2023
  • disclosed 10 Oct 2023
  • credit ziming zhang

How to fix?

Upgrade Microsoft.Native.Quic.MsQuic.Schannel to version 2.2.3 or higher.

Overview

Affected versions of this package are vulnerable to Improper Release of Memory Before Removing Last Reference ('Memory Leak') in the QUIC transport parameters when multiple instances are present or multiple calls to the decode happen. An attacker can cause a denial of service when the MsQuic server is in operation by continuously leaking memory until no more is available.

CVSS Scores

version 3.1
Expand this section

Snyk

Recommended
7.5 high
  • Attack Vector (AV)
    Network
  • Attack Complexity (AC)
    Low
  • Privileges Required (PR)
    None
  • User Interaction (UI)
    None
  • Scope (S)
    Unchanged
  • Confidentiality (C)
    None
  • Integrity (I)
    None
  • Availability (A)
    High
Expand this section

NVD

7.5 high
Expand this section

Red Hat

7.5 high