CVE-2023-29409

Severity CVSS v4.0:
Pending analysis
Type:
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
02/08/2023
Last modified:
25/11/2023

Description

Extremely large RSA keys in certificate chains can cause a client/server to expend significant CPU time verifying signatures. With fix, the size of RSA keys transmitted during handshakes is restricted to

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:golang:go:*:*:*:*:*:*:*:* 1.19.12 (excluding)
cpe:2.3:a:golang:go:*:*:*:*:*:*:*:* 1.20.0 (including) 1.20.7 (excluding)
cpe:2.3:a:golang:go:1.21.0:rc1:*:*:*:*:*:*
cpe:2.3:a:golang:go:1.21.0:rc2:*:*:*:*:*:*
cpe:2.3:a:golang:go:1.21.0:rc3:*:*:*:*:*:*