Potential denial of service when receiving empty UDP packets
MediumPublished Jun 30, 2023
### Impact An issue in s2n-quic results in the endpoint shutting down after receiving an empty UDP packet on a connection. No AWS services are affected by this issue and customers of AWS services do not need to take action. Applications using s2n-quic should upgrade their application to the most recent release of s2n-quic. Impacted version: s2n-quic v1.22.0. ### Patches The patch is included in s2n-quic [v1.23.0](https://github.com/aws/s2n-quic/releases/tag/v1.23.0). If you have any questions or comments about this advisory we ask that you contact AWS/Amazon Security via our [vulnerability reporting page](https://aws.amazon.com/security/vulnerability-reporting) or directly via email to [aws-security@amazon.com](mailto:aws-security@amazon.com). Please do not create a public GitHub issue.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| s2n-quic crates.io | < v1.23.0 | v1.23.0 |
Details and references
- Severity from
- GitHub (reviewed advisory)
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Dec 212023 | Potential URI resolution path traversal in the AWS SDK for PHP | Medium6.0 | 3.288.1 |
| Nov 62023 | Potential denial of service via crafted stream frames | Low | v1.31.0 |
| Oct 52023 | s2n-tls could negotiate signature algorithms not allowed by policy | Low | 1.3.54 |
| Jul 242023 | Potential denial of service after connection migration | Low | v1.25.0 |
| Jun 192023 | EKS overly permissive trust policies | Medium6.6 | 2.80.0+1 more |
| Feb 142023 | Issue with parsing Certificate Common Name (CN) in s2n-tls | Low | v1.3.35 |