GHSA-w3vp-jw9m-f9pm

    Dashboard / Vulnerabilities / GHSA-w3vp-jw9m-f9pm

    GHSA-w3vp-jw9m-f9pm

    Published: 13 Dec 2023Last Modified: 8 Jul 2026
    Aliases:

    Summary: Unbounded queuing of path validation messages in cloudflare-quiche

    Details: ### Impact quiche v. 0.15.0 through 0.19.0 was discovered to be vulnerable to unbounded queuing of path validation messages, which could lead to excessive resource consumption. QUIC path validation ([RFC 9000 Section 8.2](https://datatracker.ietf.org/doc/html/rfc9000#section-8.2)) requires that the recipient of a PATH_CHALLENGE frame responds by sending a PATH_RESPONSE. An unauthenticated remote attacker can exploit the vulnerability by sending PATH_CHALLENGE frames and manipulating the connection (e.g. by restricting the peer's congestion window size) so that PATH_RESPONSE frames can only be sent at the slower rate than they are received, leading to storage of path validation data in an unbounded queue. ### Patches Quiche versions greater than 0.19.0 address this problem. ### References [CVE-2023-6193](https://www.cve.org/CVERecord?id=CVE-2023-6193) [RFC 9000 Section 8.2](https://datatracker.ietf.org/doc/html/rfc9000#section-8.2)

    Affected packages

    Package

    Name: quiche

    Purl: pkg:cargo/quiche

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0.15.0
    Fixed -0.19.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-w3vp-jw9m-f9pm | CVE-DB