Processing an incomplete post-handshake message for a QUIC connection can cause a panic.
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
https://go.dev/issue/62266 | issue tracking |
https://go.dev/cl/523039 | patch |
https://groups.google.com/g/golang-dev/c/2C5vbR-UNkI/m/L1hdrPhfBAAJ | release notes |
https://pkg.go.dev/vuln/GO-2023-2044 | vendor advisory |
https://security.netapp.com/advisory/ntap-20231020-0004/ | third party advisory |
https://security.gentoo.org/glsa/202311-09 |