QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a malicious QUIC connection to cause unbounded memory growth. With fix, connections now consistently reject messages larger than 65KiB in size.
2023-09-08T17:15:28.120
2024-11-21T08:15:09.307
Modified
CVSSv3.1: 7.5 (HIGH)