rustls network-reachable panic in `Acceptor::accept`
Moderate severity
GitHub Reviewed
Published
Nov 25, 2024
to the GitHub Advisory Database
•
Updated Nov 25, 2024
Description
Published to the GitHub Advisory Database
Nov 25, 2024
Reviewed
Nov 25, 2024
Last updated
Nov 25, 2024
A bug introduced in rustls 0.23.13 leads to a panic if the received TLS ClientHello is fragmented. Only servers that use
rustls::server::Acceptor::accept()
are affected.Servers that use
tokio-rustls
'sLazyConfigAcceptor
API are affected.Servers that use
tokio-rustls
'sTlsAcceptor
API are not affected.Servers that use
rustls-ffi
'srustls_acceptor_accept
API are affected.References