CVE-2021-24029 - CVE House
Back to Database
Status published High CVE-2021-24029

A packet of death scenario is possible in mvfst via...

Vulnerability Description

A packet of death scenario is possible in mvfst via a specially crafted message during a QUIC session, which causes a crash via a failed assertion. Per QUIC specification, this particular message should be treated as a connection error. This issue affects mvfst versions prior to commit a67083ff4b8dcbb7ee2839da6338032030d712b0 and proxygen versions prior to v2021.03.15.00.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-24029

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

mvfst, proxygen
Vulnerable Versions:
a67083ff4b8dcbb7ee2839da6338032030d712b0, unspecified, v2021.03.15.00

Timeline

Official Publish: March 15th, 2021
Last Modified: August 3rd, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses (CWE)