CVE-2024-11738

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-11738
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-11738.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-11738
Aliases
Downstream
Related
Published
2024-12-06T15:15:07Z
Modified
2025-07-30T22:57:18.989538Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

A flaw was found in Rustls 0.23.13 and related APIs. This vulnerability allows denial of service (panic) via a fragmented TLS ClientHello message.

References

Affected packages

Git / github.com/ctz/rustls

Affected ranges

Type
GIT
Repo
https://github.com/ctz/rustls
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

rustls-post-quantum-v/0.*

rustls-post-quantum-v/0.1.0

v/0.*

v/0.1.0
v/0.1.1
v/0.1.2
v/0.10.0
v/0.11.0
v/0.12.0
v/0.13.0
v/0.14.0
v/0.15.0
v/0.15.1
v/0.15.2
v/0.16.0
v/0.17.0
v/0.18.0
v/0.18.1
v/0.19.0
v/0.20.0
v/0.20.0-beta1
v/0.20.0-beta2
v/0.20.1
v/0.20.2
v/0.20.3
v/0.20.4
v/0.20.5
v/0.20.6
v/0.20.7
v/0.20.8
v/0.21.0
v/0.21.0-alpha.1
v/0.21.1
v/0.21.2
v/0.22.0
v/0.23.0
v/0.23.1
v/0.23.10
v/0.23.11
v/0.23.12
v/0.23.13
v/0.23.2
v/0.23.3
v/0.23.4
v/0.23.5
v/0.23.6
v/0.23.7
v/0.23.8
v/0.23.9
v/0.5.0
v/0.5.1
v/0.5.2
v/0.5.3
v/0.5.4
v/0.5.5
v/0.5.6
v/0.5.7
v/0.5.8
v/0.6.0
v/0.7.0
v/0.8.0
v/0.9.0