Skip to content
AWSGHSA-gj4j-vp5f-86cf

Potential denial of service when sending version negotiation or close packets

MediumPublished May 5, 2022

Some sender components could potentially panic when writing packets, leading to the endpoint shutting down. AWS Services are not affected by this issue. Customers using `s2n-quic` in their applications should update to the most recent version. All versions of `s2n-quic` before and including v1.1.0 are affected by this issue. Customers should upgrade to v1.1.1. Note that this issue does not affect `s2n-tls`.

GitHub advisory

Affected versions

PackageAffectedFixed in
s2n-quic
crates.io
< v1.1.1v1.1.1
Details and references

More AWS advisories

All AWS
Advisory
Privilege Escalation Vector in CloudWatch Agent for Windows
High7.1Dec 10, 2022
Issue with configuring session ticket names in s2n-tls
MediumSep 27, 2022
Server denial-of-service by using sslv2 message format in a HelloRetryRequest handshake
LowSep 27, 2022
Partial Path Traversal in aws-cpp-sdk-transfer
MediumAug 9, 2022
Partial Path Traversal in com.amazonaws:aws-java-sdk-s3
High7.9Jul 15, 2022
Security vulnerability in a third party software, Slurm < 20.11.9 and 21.08.8
CriticalMay 16, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.