Impact
libp2p‑rust exposes a crash in its QUIC transport when a remote peer presents a valid short‑lived TLS certificate that expires during the QUIC handshake. The implementation re‑parses the certificate after the handshake and, using an unsafe `expect` call, aborts the process if the certificate has become invalid. An attacker can coordinate the timing of a connection to trigger this race condition, causing the entire listening application to terminate.
Affected Systems
The vulnerable component is the libp2p‑quic module in the Rust implementation of libp2p, distributed as libp2p:rust-libp2p. All releases before version 0.13.1 are affected. Any Rust application that links against libp2p:rust-libp2p 0.13.0 or earlier and exposes a QUIC listener is potentially susceptible.
Risk and Exploitability
The CVSS score of 8.2 indicates high severity. The EPSS score is below 1 %, suggesting a low probability of abuse in the near term. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is remote, requiring an attacker to initiate a QUIC connection to a vulnerable node and time a certificate expiration during the handshake. Although no public exploits are known, the crash and high severity warrant immediate patching.
OpenCVE Enrichment
Github GHSA