Unlimited Resource Allocation Vulnerability Affects Cloudflare Quiche
CVE-2024-1765

7.5HIGH

Key Information:

Vendor

Cloudflare

Status
Vendor
CVE Published:
12 March 2024

What is CVE-2024-1765?

Cloudflare Quiche versions up to 0.20.0 are susceptible to an unlimited resource allocation vulnerability, which can lead to uncontrolled memory usage on systems running the quiche server or client. An attacker could exploit this issue by sending an unlimited number of 1-RTT CRYPTO frames following a successful QUIC handshake. The exploitation can occur throughout the duration of the connection, and this period can be extended actively by the attacker. Affected users are advised to upgrade to Cloudflare Quiche versions 0.19.2 or 0.20.1, which contain a fix for this vulnerability.

Affected Version(s)

quiche Rust 0.15.0

quiche Rust 0.20.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Marten Seeman (@marten-seemann)
.