Rustls is a modern TLS library written in Rust. `rustls::ConnectionCommon::complete_io` could fall into an infinite loop based on network input. When using a blocking rustls server, if a client send a `close_notify` message immediately after `client_hello`, the server's `complete_io` will get in an infinite loop. This vulnerability is fixed in 0.23.5, 0.22.4, and 0.21.11.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-04-19T16:05:44.050Z

Updated: 2024-08-02T02:13:40.195Z

Reserved: 2024-04-16T14:15:26.876Z

Link: CVE-2024-32650

cve-icon Vulnrichment

Updated: 2024-04-22T14:56:20.057Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-04-19T16:15:10.940

Modified: 2024-11-21T09:15:23.803

Link: CVE-2024-32650

cve-icon Redhat

No data.