Description
Unbounded memory allocation in the CRYPTO frame reassembler in s2n-quic before 1.8.2 may allow an unauthenticated remote actor to cause a denial of service (degraded availability) by sending crafted QUIC Initial packets. To remediate this issue, users should upgrade to v1.8.2.
Problem types
CWE-770: Allocation of Resources Without Limits or Throttling
Product status
Any version
References
github.com/aws/s2n-quic/releases/tag/v1.82.0
aws.amazon.com/security/security-bulletins/2026-042-aws/
github.com/...n-quic/security/advisories/GHSA-9q54-f358-3fqf