Overview
About vulnerability
ASP.NET Core Kestrel in Microsoft .NET 8.0 before 8.0.22 and .NET 9.0 before 9.0.11 allows a remote attacker to cause excessive CPU consumption by sending a crafted QUIC packet, because of an incorrect exit condition for HTTP/3 Encoder/Decoder stream processing.Details
- Affected product:
- Debian 12 , Debian 13 , Windows 10
- Affected packages:
- dotnet @ 7.0 (+6 more)