GHSA-hxp2-xqf3-v83h: Panic during unmarshal of Hello Verify Request in github.com/pion/dtls/v2
5.9
CVSS Score
3.1
Basic Information
CVE ID
-
GHSA ID
EPSS Score
-
CWE
Published
2/7/2023
Updated
6/13/2023
KEV Status
No
Technology
Go
Technical Details
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| github.com/pion/dtls/v2 | go | < 2.2.4 | 2.2.4 |
| github.com/pion/dtls | go | <= 1.5.4 |
Vulnerability Intelligence
Miggo AI
Root Cause Analysis
- The commit diff shows critical buffer check additions in MessageServerHello.Unmarshal
- Go vulnerability report GO-2023-1535 explicitly lists MessageServerHello.Unmarshal as affected
- CWE-125 matches the OOB read pattern observed in the pre-patch code
- Advisory descriptions specifically mention Server Hello unmarshalling as the vulnerable operation
- The patch adds a 'currOffset+2' check before CipherSuiteID access, indicating this was the missing safeguard