Intel

AIKIDO-2026-562254

quinn-proto is vulnerable to Denial of Service (DoS)

Denial of Service (DoS)GHSA-ppcp-v39w-8jq2 Published Yesterday

75

High Risk

This Affects:

RUSTquinn-proto
0.11.17 - 0.11.17
Fixed in 0.11.18
Are you affected? Scan for Free

TL;DR

quinn-proto's outgoing datagram queue keeps a payload_bytes count of buffered data to bound memory use. When a full buffer evicts queued datagrams, both Datagrams::send and the buffer's own eviction logic subtract the evicted size from payload_bytes, so the reduction is counted twice. Sustained eviction drains the counter past its true value, causing an overflow panic in debug builds or a desynchronization panic in release builds inside send_datagram. The fix removes the redundant subtraction at the call site.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you send datagrams with send_datagram.

Background info

quinn-proto is vulnerable to Denial of Service (DoS) in versions 0.11.17 - 0.11.17.

How to fix this

Upgrade the quinn-proto library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform