Uploaded image for project: 'Hybrid Cloud Console'
  1. Hybrid Cloud Console
  2. RHCLOUD-43661

CVE-2025-59530 remediations/insights-remediations-frontend: quic-go Crash Due to Premature HANDSHAKE_DONE Frame [services-remediations]

XMLWordPrintable

    • False
    • Hide

      None

      Show
      None
    • False
    • None
    • insights-ops-1
    • None
    • CVEORG
    • CVE-2025-59530
    • 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
    • (CWE-617|CWE-755)
    • remediations/insights-remediations-frontend
    • github.com/quic-go/quic-go
    • False
    • Moderate

      Security Tracking Issue

      Do not make this issue public.

      Flaw:


      quic-go Crash Due to Premature HANDSHAKE_DONE Frame

      quic-go is an implementation of the QUIC protocol in Go. In versions prior to 0.49.0, 0.54.1, and 0.55.0, a misbehaving or malicious server can cause a denial-of-service (DoS) attack on the quic-go client by triggering an assertion failure, leading to a process crash. This requires no authentication and can be exploited during the handshake phase. This was observed in the wild with certain server implementations. quic-go needs to be able to handle misbehaving server implementations, including those that prematurely send a HANDSHAKE_DONE frame. Versions 0.49.0, 0.54.1, and 0.55.0 discard Initial keys when receiving a HANDSHAKE_DONE frame, thereby correctly handling premature HANDSHAKE_DONE frames.

      ~~~

      The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
      https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams

      Tracker accuracy feedback form: https://docs.google.com/forms/d/e/1FAIpQLSfa6zTaEGohRdiIqGVAvWTSAL0kpO_DkkEICuIHzQHFwmKswg/viewform

              Unassigned Unassigned
              rh-ee-jmoroney Jon Moroney
              Votes:
              0 Vote for this issue
              Watchers:
              7 Start watching this issue

                Created:
                Updated: