Rustls is a modern TLS library written in Rust. `rustls::ConnectionCommon::complete_io` could fall into an infinite loop based on network input. When using a blocking rustls server, if a client send a `close_notify` message immediately after `client_hello`, the server's `complete_io` will get in an infinite loop. This vulnerability is fixed in 0.23.5, 0.22.4, and 0.21.11.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-04-19T16:05:44.050Z
Updated: 2024-08-02T02:13:40.195Z
Reserved: 2024-04-16T14:15:26.876Z
Link: CVE-2024-32650
Vulnrichment
Updated: 2024-04-22T14:56:20.057Z
NVD
Status : Awaiting Analysis
Published: 2024-04-19T16:15:10.940
Modified: 2024-11-21T09:15:23.803
Link: CVE-2024-32650
Redhat
No data.