Skip to content
CloudflareGHSA-pjrj-h4fg-6gm4

Resource exhaustion via memory leak in tokio-boring

Medium5.3CVE-2023-6180 · Published Dec 5, 2023

### Impact The tokio-boring library in version 4.0.0 is affected by a memory leak issue that can lead to excessive resource consumption and potential DoS by resource exhaustion. The `set_ex_data` function used by the library did not deallocate memory used by pre-existing data in memory each time after completing a TLS connection causing the program to consume more resources with each new connection. ### Patches The issue is fixed in version 4.1.0 of tokio-boring. ### References [CVE-2023-6180 at cve.org](https://www.cve.org/CVERecord?id=CVE-2023-6180)

GitHub advisory

Affected versions

PackageAffectedFixed in
tokio-boring
crates.io
< 4.1.04.1.0
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Severity from
GitHub (reviewed advisory)
Weakness
CWE-401, CWE-404

More Cloudflare advisories

All Cloudflare
Advisory
Kyber: timing side-channel (kyberslash2)
HighJan 8, 2024
Arbitrary remote code execution within `wrangler dev` Workers sandbox
High8.5Dec 29, 2023
Arbitrary remote file read in Wrangler dev server
Medium6.9Dec 29, 2023
Server-Side Request Forgery (SSRF) in Miniflare
High8.0Dec 29, 2023
Unbounded queuing of path validation messages in cloudflare-quiche
Medium5.3Dec 12, 2023
WebSocket message can cause crash
MediumNov 21, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.