Skip to content

Allocated memory not freed when session ticket is used

Low
zaherd published GHSA-q4mv-c662-pgwg Dec 14, 2020

Package

s2n

Affected versions

< v0.10.23

Patched versions

v0.10.23

Description

s2n fails to free allocated memory when the session ticket decryption method fails. This could cause the host to run out of memory and force the application to restart.

Customers of AWS services do not need to take action. s2n users who are using session resumption in their applications should update to the most recent s2n version.

All versions of s2n from commit cc339f5 to 360f620 are affected by this issue. s2n users should fetch s2n commit c422355

Severity

Low

CVE ID

No known CVE

Weaknesses

No CWEs