|
Bugzilla – Full Text Bug Listing |
| Summary: | VUL-0: CVE-2024-22189: caddy: quic-go: memory exhaustion attack against QUIC's connection ID mechanism | ||
|---|---|---|---|
| Product: | [openSUSE] openSUSE Tumbleweed | Reporter: | Camila Camargo de Matos <camila.matos> |
| Component: | Security | Assignee: | Alexandre Vicenzi <alexandre.vicenzi> |
| Status: | NEW --- | QA Contact: | E-mail List <qa-bugs> |
| Severity: | Major | ||
| Priority: | P3 - Medium | CC: | camila.matos, jkowalczyk, security-team, smash_bz |
| Version: | Current | ||
| Target Milestone: | --- | ||
| Hardware: | Other | ||
| OS: | Other | ||
| URL: | https://smash.suse.de/issue/400376/ | ||
| Whiteboard: | |||
| Found By: | Security Response Team | Services Priority: | |
| Business Priority: | Blocker: | --- | |
| Marketing QA Status: | --- | IT Deployment: | --- |
| Bug Depends on: | |||
| Bug Blocks: | 1222461 | ||
|
Description
Camila Camargo de Matos
2024-04-08 12:37:44 UTC
Go module quic-go is affected by CVE-2024-22189 and this module is embedded in openSUSE:Factory/caddy (quic-go version 0.40.0). The issue has been fixed upstream in https://github.com/caddyserver/caddy/pull/6176 but there's no new release of Caddy yet. This was fixed in https://build.opensuse.org/request/show/1178203. This is an autogenerated message for OBS integration: This bug (1222468) was mentioned in https://build.opensuse.org/request/show/1188159 Backports:SLE-15-SP5 / caddy |