{"schema_version":"1.9.0","id":"GHSA-c86p-w88r-qvqr","published":"2025-05-09T18:30:38Z","modified":"2026-09-10T03:50:24.552767536Z","withdrawn":"2025-12-29T21:36:51Z","aliases":["CVE-2025-4432","GHSA-4p46-pwfr-66x6","GO-2025-3678","RUSTSEC-2025-0009"],"summary":"Duplicate Advisory: ring has some AES functions that may panic when overflow checking is enabled in","details":"### Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-4p46-pwfr-66x6. This link is maintained to preserve external references.\n\n### Original Description\nA flaw was found in Rust's Ring package. A panic may be triggered when overflow checking is enabled. In the QUIC protocol, this flaw allows an attacker to induce this panic by sending a specially crafted packet. It will likely occur unintentionally in 1 out of every 2**32 packets sent or received.","affected":[{"package":{"name":"ring","ecosystem":"crates.io","purl":"pkg:cargo/ring"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.17.13"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/05/GHSA-c86p-w88r-qvqr/GHSA-c86p-w88r-qvqr.json"}}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-4432"},{"type":"WEB","url":"https://github.com/briansmith/ring/pull/2447"},{"type":"WEB","url":"https://github.com/briansmith/ring/commit/ec2d3cf1d91f148c84e4806b4f0b3c98f6df3b38"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2025-4432"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2350655"},{"type":"PACKAGE","url":"https://github.com/briansmith/ring"},{"type":"WEB","url":"https://github.com/briansmith/ring/blob/main/RELEASES.md#version-01712-2025-03-05"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2025-0009.html"}],"database_specific":{"cwe_ids":["CWE-770"],"github_reviewed":true,"github_reviewed_at":"2025-05-09T19:42:41Z","nvd_published_at":"2025-05-09T16:15:25Z","severity":"MODERATE"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}]}