HomeDefault status
unaffected
Any version before 1.25.9
affected
1.26.0-0 (semver) before 1.26.2
affected
Description
If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.
Problem types
Product status
Any version before 1.25.9
1.26.0-0 (semver) before 1.26.2
Credits
Jakub Ciolek - https://ciolek.dev/
References
groups.google.com/g/golang-announce/c/0uYbvbPZRWU