{"schema_version":"1.7.5","id":"CVE-2024-32650","published":"2024-04-19T16:05:44.050Z","modified":"2026-07-16T10:14:28.019052298Z","aliases":["GHSA-6g7w-8wpp-frhj","RUSTSEC-2024-0336"],"related":["CGA-f8qw-rjr9-54v6","SUSE-SU-2025:02809-1","SUSE-SU-2025:02810-1","SUSE-SU-2025:02811-1","SUSE-SU-2025:03629-1","SUSE-SU-2025:20057-1","SUSE-SU-2026:3022-1","openSUSE-SU-2024:0130-1","openSUSE-SU-2024:13893-1","openSUSE-SU-2024:13903-1","openSUSE-SU-2024:13904-1","openSUSE-SU-2024:13912-1","openSUSE-SU-2024:13917-1","openSUSE-SU-2024:13923-1","openSUSE-SU-2024:13961-1","openSUSE-SU-2024:13969-1","openSUSE-SU-2024:14424-1"],"summary":"Rustls vulnerable to an infinite loop in rustls::conn::ConnectionCommon::complete_io() with proper client input","details":"Rustls is a modern TLS library written in Rust. `rustls::ConnectionCommon::complete_io` could fall into an infinite loop based on network input. When using a blocking rustls server, if a client send a `close_notify` message immediately after `client_hello`, the server's `complete_io` will get in an infinite loop. This vulnerability is fixed in 0.23.5, 0.22.4, and 0.21.11.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/rustls/rustls","events":[{"introduced":"eb0791bc94cfdc4c42f743902a35074ce58ced11"},{"introduced":"4d1b762b5328a1714862ba73ec72d5522fe0c049"},{"introduced":"45197b807cf0699c842fcb85eb8eca555c74cc04"},{"introduced":"bc754a4fbb586beb7b1dfce38ab880fd90c0e422"},{"fixed":"14cb5d2eac709f6c9bd46c697f090bb1f1543db1"},{"fixed":"ae277befb5061bbd4c44fea1c2697f2da5b2f6fa"},{"fixed":"7b8d1dbc1e666dc4d83640c64e96d257d39cfda4"},{"fixed":"2123576840aa31043a31b0770e6572136fbe0c2d"},{"fixed":"6e938bcfe82a9da7a2e1cbf10b928c7eca26426e"},{"fixed":"f45664fbded03d833dffd806503d3c8becd1b71e"}],"database_specific":{"extracted_events":[{"introduced":"0.23.0"},{"fixed":"0.23.5"},{"introduced":"0.22.0"},{"fixed":"0.22.4"},{"introduced":"0.21.0"},{"fixed":"0.21.11"},{"introduced":"= 0.20.0"},{"last_affected":"= 0.20.0"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["= 0.20.0","v/0.22.3","v/0.21.10","v/0.23.4","v/0.23.3","rustls-post-quantum-v/0.1.0","v/0.23.2","v/0.23.1","v/0.23.0","v/0.22.2","v/0.22.1","v/0.21.9","v/0.22.0","v/0.21.8","v/0.21.7","v/0.21.6","v/0.21.5","v/0.21.4","v/0.21.3","v/0.21.2","v/0.21.1","v/0.21.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-32650.json"}}],"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/32xxx/CVE-2024-32650.json"},{"type":"ADVISORY","url":"https://github.com/rustls/rustls/security/advisories/GHSA-6g7w-8wpp-frhj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-32650"},{"type":"FIX","url":"https://github.com/rustls/rustls/commit/2123576840aa31043a31b0770e6572136fbe0c2d"},{"type":"FIX","url":"https://github.com/rustls/rustls/commit/6e938bcfe82a9da7a2e1cbf10b928c7eca26426e"},{"type":"FIX","url":"https://github.com/rustls/rustls/commit/f45664fbded03d833dffd806503d3c8becd1b71e"}],"database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-835"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/32xxx/CVE-2024-32650.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}