Description
A packet of death scenario is possible in mvfst via a specially crafted message during a QUIC session, which causes a crash via a failed assertion. Per QUIC specification, this particular message should be treated as a connection error. This issue affects mvfst versions prior to commit a67083ff4b8dcbb7ee2839da6338032030d712b0 and proxygen versions prior to v2021.03.15.00.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-10949 | A packet of death scenario is possible in mvfst via a specially crafted message during a QUIC session, which causes a crash via a failed assertion. Per QUIC specification, this particular message should be treated as a connection error. This issue affects mvfst versions prior to commit a67083ff4b8dcbb7ee2839da6338032030d712b0 and proxygen versions prior to v2021.03.15.00. |
References
History
No history.
Status: PUBLISHED
Assigner: facebook
Published:
Updated: 2024-08-03T19:21:17.115Z
Reserved: 2021-01-13T00:00:00.000Z
Link: CVE-2021-24029
No data.
Status : Modified
Published: 2021-03-15T22:15:13.530
Modified: 2024-11-21T05:52:14.570
Link: CVE-2021-24029
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD