Description
The tokio-boring library in version 4.0.0 is affected by a memory leak issue that can lead to excessive resource consumption and potential DoS by resource exhaustion. The set_ex_data function used by the library did not deallocate memory used by pre-existing data in memory each time after completing a TLS connection causing the program to consume more resources with each new connection.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-3262 | The tokio-boring library in version 4.0.0 is affected by a memory leak issue that can lead to excessive resource consumption and potential DoS by resource exhaustion. The set_ex_data function used by the library did not deallocate memory used by pre-existing data in memory each time after completing a TLS connection causing the program to consume more resources with each new connection. |
Github GHSA |
GHSA-pjrj-h4fg-6gm4 | tokio-boring vulnerable to resource exhaustion via memory leak |
References
History
No history.
Status: PUBLISHED
Assigner: cloudflare
Published:
Updated: 2024-08-02T08:21:17.825Z
Reserved: 2023-11-16T19:15:23.367Z
Link: CVE-2023-6180
No data.
Status : Modified
Published: 2023-12-05T15:15:08.703
Modified: 2024-11-21T08:43:18.253
Link: CVE-2023-6180
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA