DEBIAN-CVE-2022-30591

Source
https://security-tracker.debian.org/tracker/CVE-2022-30591
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-30591.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2022-30591
Upstream
Published
2022-07-06T12:15:08.173Z
Modified
2026-03-11T07:34:17.818979Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

quic-go through 0.27.0 allows remote attackers to cause a denial of service (CPU consumption) via a Slowloris variant in which incomplete QUIC or HTTP/3 requests are sent. This occurs because mtu_discoverer.go misparses the MTU Discovery service and consequently overflows the probe timer. NOTE: the vendor's position is that this behavior should not be listed as a vulnerability on the CVE List

References

Affected packages

Debian:11
golang-github-lucas-clemente-quic-go

Package

Name
golang-github-lucas-clemente-quic-go
Purl
pkg:deb/debian/golang-github-lucas-clemente-quic-go?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.19.3-1
0.24.0-1
0.25.0-1
0.26.0-1~bpo11+1
0.26.0-1
0.29.0-1~bpo11+1
0.29.0-1~bpo11+2
0.29.0-1
0.29.2-1
0.29.2-2
0.29.2-3
0.37.0-1
0.37.4-1~bpo12+1
0.37.4-1
0.38.2-1
0.38.2-2
0.46.0-1
0.46.0-2~bpo12+1
0.46.0-2
0.50.0-1
0.50.1-1
0.50.1-2
0.54.0-1
0.54.0-2
0.54.0-3
0.54.1-1
0.55.0-1
0.59.0-1
0.59.0-2

Ecosystem specific

{
    "urgency": "unimportant"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-30591.json"
Debian:12
golang-github-lucas-clemente-quic-go

Package

Name
golang-github-lucas-clemente-quic-go
Purl
pkg:deb/debian/golang-github-lucas-clemente-quic-go?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.29.0-1
0.29.2-1
0.29.2-2
0.29.2-3
0.37.0-1
0.37.4-1~bpo12+1
0.37.4-1
0.38.2-1
0.38.2-2
0.46.0-1
0.46.0-2~bpo12+1
0.46.0-2
0.50.0-1
0.50.1-1
0.50.1-2
0.54.0-1
0.54.0-2
0.54.0-3
0.54.1-1
0.55.0-1
0.59.0-1
0.59.0-2

Ecosystem specific

{
    "urgency": "unimportant"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-30591.json"
Debian:13
golang-github-lucas-clemente-quic-go

Package

Name
golang-github-lucas-clemente-quic-go
Purl
pkg:deb/debian/golang-github-lucas-clemente-quic-go?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.50.1-2
0.54.0-1
0.54.0-2
0.54.0-3
0.54.1-1
0.55.0-1
0.59.0-1
0.59.0-2

Ecosystem specific

{
    "urgency": "unimportant"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-30591.json"
Debian:14
golang-github-lucas-clemente-quic-go

Package

Name
golang-github-lucas-clemente-quic-go
Purl
pkg:deb/debian/golang-github-lucas-clemente-quic-go?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.50.1-2
0.54.0-1
0.54.0-2
0.54.0-3
0.54.1-1
0.55.0-1
0.59.0-1
0.59.0-2

Ecosystem specific

{
    "urgency": "unimportant"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-30591.json"