GHSA-4p46-pwfr-66x6

    Dashboard / Vulnerabilities / GHSA-4p46-pwfr-66x6

    GHSA-4p46-pwfr-66x6

    Published: 7 Mar 2025Last Modified: 10 Sept 2026

    Summary: Some AES functions may panic when overflow checking is enabled in ring

    Details: `ring::aead::quic::HeaderProtectionKey::new_mask()` may panic when overflow checking is enabled. In the QUIC protocol, an attacker can induce this panic by sending a specially-crafted packet. Even unintentionally it is likely to occur in 1 out of every 2**32 packets sent and/or received. On 64-bit targets operations using `ring::aead::{AES_128_GCM, AES_256_GCM}` may panic when overflow checking is enabled, when encrypting/decrypting approximately 68,719,476,700 bytes (about 64 gigabytes) of data in a single chunk. Protocols like TLS and SSH are not affected by this because those protocols break large amounts of data into small chunks. Similarly, most applications will not attempt to encrypt/decrypt 64GB of data in one chunk. Overflow checking is not enabled in release mode by default, but `RUSTFLAGS="-C overflow-checks"` or `overflow-checks = true` in the Cargo.toml profile can override this. Overflow checking is usually enabled by default in debug mode.

    Affected packages

    Package

    Name: ring

    Purl: pkg:cargo/ring

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -0.17.12

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-4p46-pwfr-66x6 | CVE-DB