icon

We found results for “

CVE-2024-32650

Date: April 19, 2024

Rustls is a modern TLS library written in Rust. "rustls::ConnectionCommon::complete_io" could fall into an infinite loop based on network input. When using a blocking rustls server, if a client send a "close_notify" message immediately after "client_hello", the server's "complete_io" will get in an infinite loop. This vulnerability is fixed in 0.23.5, 0.22.4, and 0.21.11.

Language: C

Severity Score

Severity Score

Weakness Type (CWE)

Loop with Unreachable Exit Condition ('Infinite Loop')

CWE-835

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): NONE
Integrity (I): NONE
Availability (A): HIGH

Do you need more information?

Contact Us