{"id":"DEBIAN-CVE-2024-32650","details":"Rustls is a modern TLS library written in Rust. `rustls::ConnectionCommon::complete_io` could fall into an infinite loop based on network input. When using a blocking rustls server, if a client send a `close_notify` message immediately after `client_hello`, the server's `complete_io` will get in an infinite loop. This vulnerability is fixed in 0.23.5, 0.22.4, and 0.21.11.","modified":"2026-09-15T09:03:02.831450274Z","published":"2024-04-19T16:15:10.940Z","upstream":["CVE-2024-32650"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2024-32650"}],"affected":[{"package":{"name":"rust-rustls","ecosystem":"Debian:12","purl":"pkg:deb/debian/rust-rustls?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.20.8-4","0.20.8-4.1","0.20.8-4.2","0.21.10-1","0.21.12-1","0.21.12-2","0.21.12-3","0.21.12-4","0.21.12-5","0.21.12-6","0.21.12-7","0.21.12-8","0.21.12-9","0.21.5-1","0.21.5-2","0.21.5-3","0.21.5-4","0.21.5-5","0.21.6-1","0.21.6-2","0.21.6-3","0.21.6-4","0.21.7-1","0.21.8-1","0.21.8-2","0.21.8-3","0.21.8-3.1","0.21.9-1","0.23.16-1","0.23.20+ds-1","0.23.20+ds-10","0.23.20+ds-2","0.23.20+ds-3","0.23.20+ds-4","0.23.20+ds-5","0.23.20+ds-6","0.23.20+ds-7","0.23.20+ds-8","0.23.20+ds-9","0.23.25+ds-1","0.23.26+ds-1","0.23.31+ds-1","0.23.31+ds-2","0.23.31+ds-3","0.23.31+ds-4","0.23.31+ds-5","0.23.31+ds-6","0.23.31+ds-7","0.23.32+ds-1","0.23.32+ds-2","0.23.33+ds-1","0.23.33+ds-2","0.23.33+ds-3","0.23.33+ds-4","0.23.35+ds-1","0.23.36+ds-1","0.23.37+ds-1","0.23.37+ds-2","0.23.37+ds-3","0.23.38+ds-1","0.23.40+ds-1","0.23.41+ds-1","0.23.43+ds-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-32650.json"}},{"package":{"name":"rust-rustls","ecosystem":"Debian:13","purl":"pkg:deb/debian/rust-rustls?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.21.12-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-32650.json"}},{"package":{"name":"rust-rustls","ecosystem":"Debian:14","purl":"pkg:deb/debian/rust-rustls?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.21.12-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-32650.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}