{"id":"GHSA-3q6m-v84f-6p9h","summary":"quic-go vulnerable to pointer dereference that can lead to panic","details":"quic-go is an implementation of the [QUIC](https://datatracker.ietf.org/doc/html/rfc9000) transport protocol in Go. By serializing an ACK frame after the CRYTPO that allows a node to complete the handshake, a remote node could trigger a nil pointer dereference (leading to a panic) when the node attempted to drop the Handshake packet number space.\n\n**Impact**\n\nAn attacker can bring down a quic-go node with very minimal effort. Completing the QUIC handshake only requires sending and receiving a few packets.\n\n**Patches**\n\n[v0.37.3](https://github.com/quic-go/quic-go/releases/tag/v0.37.3) contains a patch. Versions before v0.37.0 are not affected.","aliases":["CVE-2023-46239","GO-2023-2160"],"modified":"2026-09-10T03:49:24.666665738Z","published":"2023-10-30T15:08:05Z","database_specific":{"github_reviewed_at":"2023-10-30T15:08:05Z","nvd_published_at":"2023-10-31T16:15:09Z","cwe_ids":["CWE-248","CWE-476"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/quic-go/quic-go/security/advisories/GHSA-3q6m-v84f-6p9h"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-46239"},{"type":"WEB","url":"https://github.com/quic-go/quic-go/commit/b6a4725b60f1fe04e8f1ddcc3114e290fcea1617"},{"type":"PACKAGE","url":"https://github.com/quic-go/quic-go"},{"type":"WEB","url":"https://github.com/quic-go/quic-go/releases/tag/v0.37.3"}],"affected":[{"package":{"name":"github.com/quic-go/quic-go","ecosystem":"Go","purl":"pkg:golang/github.com/quic-go/quic-go"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.37.0"},{"fixed":"0.37.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/10/GHSA-3q6m-v84f-6p9h/GHSA-3q6m-v84f-6p9h.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}