DirectorySecurity Advisories
Sign In
Security Advisories

CGA-26mh-2j9v-93f6

Published

Last updated

https://images.chainguard.dev/security/CGA-26mh-2j9v-93f6
Package

pixi

Latest Update
Fixed
Fixed Version

0.37.0-r1

Aliases
  • GHSA-qg5g-gv98-5ffh

Severity

Unknown

Summary

rustls network-reachable panic in Acceptor::accept

Description

A bug introduced in rustls 0.23.13 leads to a panic if the received TLS ClientHello is fragmented. Only servers that use rustls::server::Acceptor::accept() are affected.

Servers that use tokio-rustls's LazyConfigAcceptor API are affected.

Servers that use tokio-rustls's TlsAcceptor API are not affected.

Servers that use rustls-ffi's rustls_acceptor_accept API are affected.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images