A bug introduced in rustls 0.23.13 leads to a panic if the received
TLS ClientHello is fragmented. Only servers that use
rustls::server::Acceptor::accept() are affected.
Servers that use tokio-rustls's LazyConfigAcceptor API are affected.
Servers that use tokio-rustls's TlsAcceptor API are not affected.
Servers that use rustls-ffi's rustls_acceptor_accept API are affected.
rustls
0.23.14
>=0.23.18
>=0.23, <0.23.13,<0.23
A bug introduced in rustls 0.23.13 leads to a panic if the received TLS ClientHello is fragmented. Only servers that use
rustls::server::Acceptor::accept()
are affected.Servers that use
tokio-rustls
'sLazyConfigAcceptor
API are affected.Servers that use
tokio-rustls
'sTlsAcceptor
API are not affected.Servers that use
rustls-ffi
'srustls_acceptor_accept
API are affected.See advisory page for additional details.