Impact
The vulnerability exists in rustls-webpki where parsing a CRL containing an empty BIT STRING fails to reject a named-bit BIT STRING with content [0x00], causing an underflow in bit_string_flags() that results in a panic. This crash is triggered through the BorrowedCertRevocationList::from_der() API and leads to denial of service for applications that enable CRL revocation checking. A properly crafted certificate revocation list can bring a rustls-enabled server to a halt.
Affected Systems
The affected library is rustls-webpki. Vulnerable versions include 0.103.12 and any 0.104.0‑alpha release before 0.104.0‑alpha.7. The patch is available in 0.103.13 and 0.104.0‑alpha.7 onward. Systems that use rustls at these versions and enable revocation options are at risk.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity vulnerability. The EPSS score is reported as < 1%, and the absence of a KEV listing suggests no widespread exploitation has yet been observed. The exploit requires an application that explicitly opts in to CRL verification and is fed a CRL from an attacker-controlled source, which is usually supplied over the network. Thus, a malicious actor could deliver a crafted CRL to any rustls-enabled service that uses CRL revocation checking, causing the service to panic and crash. The lack of default revocation checking in rustls mitigates the risk for most deployments; however, services that have enabled RevocationOptions are susceptible to this denial of service.
OpenCVE Enrichment