H2O Quicly
- <= dccf5d4
A denial-of-service vulnerability has been identified in H2O Quicly, an implementation of the IETF QUIC protocol. This issue arises from an assertion failure that occurs when the total number of valid handshake messages received over a CRYPTO stream within a single packet number space exceeds 32KB. The vulnerability is present in versions of Quicly prior to the commit 937d0e9.
Exceeding the CRYPTO stream limit causes an assertion failure, leading to a denial-of-service condition.
The vulnerability can be reproduced by sending a large number of valid handshake messages over a CRYPTO stream in a single packet number space, exceeding the 32KB limit. This can be done using a QUIC client that allows for manipulation of the handshake message size and stream data.
Users can update to Quicly version 8b178e6 or later, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.