NULL Pointer Dereference Affecting github.com/quic-go/quic-go package, versions >=0.37.0 <0.37.3


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.77% (51st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMQUICGOQUICGO-6039896
  • published31 Oct 2023
  • disclosed30 Oct 2023
  • creditUnknown

Introduced: 30 Oct 2023

CVE-2023-46239  (opens in a new tab)
CWE-476  (opens in a new tab)

How to fix?

Upgrade github.com/quic-go/quic-go to version 0.37.3 or higher.

Overview

Affected versions of this package are vulnerable to NULL Pointer Dereference via the ACK frame serialization after the CRYTPO that allows a node to complete the handshake. An attacker can bring down a node with very minimal effort when the node attempts to drop the Handshake packet number space.

CVSS Base Scores

version 3.1