Panic Vulnerability in Rust's Rustls Crate Affecting TLS ClientHello
CVE-2024-58254
5.3MEDIUM
What is CVE-2024-58254?
A vulnerability has been identified in the rustls crate, specifically in versions prior to 0.23.18. When the rustls::server::Acceptor::accept function is invoked, it may encounter a panic due to a fragmented TLS ClientHello message. This can lead to unexpected behavior, impacting the stability and security of applications relying on this crate. Developers using rustls need to update to the latest version to mitigate potential security risks.
Affected Version(s)
Rustls 0.23.13 < 0.23.18