Potential denial of service via crafted stream frames
LowPublished Nov 6, 2023
### Impact An issue in s2n-quic could result in unnecessary resource utilization when peers open streams beyond advertised limits. Impacted versions: <= v1.30.0. ### Patches The patch is included in v1.31.0 [1]. ### Workarounds There is no workaround. Applications using s2n-quic should upgrade to the most recent release of s2n-quic. If you have any questions or comments about this advisory, we ask that you contact AWS Security via our vulnerability reporting page [2] or directly via email to [aws-security@amazon.com](mailto:aws-security@amazon.com). Please do not create a public GitHub issue. [1] https://github.com/aws/s2n-quic/releases/tag/v1.31.0 [2] https://aws.amazon.com/security/vulnerability-reporting
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| s2n-quic crates.io | < v1.31.0 | v1.31.0 |
Details and references
- Severity from
- GitHub (reviewed advisory)
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 22024 | GHSA for sagemaker.base_deserializers.NumpyDeserializer | High7.8 | 2.218.0 |
| Dec 212023 | Potential URI resolution path traversal in the AWS SDK for PHP | Medium6.0 | 3.288.1 |
| Oct 52023 | s2n-tls could negotiate signature algorithms not allowed by policy | Low | 1.3.54 |
| Jul 242023 | Potential denial of service after connection migration | Low | v1.25.0 |
| Jun 302023 | Potential denial of service when receiving empty UDP packets | Medium | v1.23.0 |
| Jun 192023 | EKS overly permissive trust policies | Medium6.6 | 2.80.0+1 more |