{"id":"CVE-2024-32650","aliases":["GHSA-6g7w-8wpp-frhj","RUSTSEC-2024-0336"],"url":"https://o3.security/vulnerability/CVE-2024-32650","summary":"Rustls vulnerable to an infinite loop in rustls::conn::ConnectionCommon::complete_io() with proper client input","details":"Rustls is a modern TLS library written in Rust. `rustls::ConnectionCommon::complete_io` could fall into an infinite loop based on network input. When using a blocking rustls server, if a client send a `close_notify` message immediately after `client_hello`, the server's `complete_io` will get in an infinite loop. This vulnerability is fixed in 0.23.5, 0.22.4, and 0.21.11.","published":"2024-04-19T16:05:44.050Z","modified":"2026-08-12T18:48:04.634802700Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"rustls","fixedVersion":"0.23.5"},{"ecosystem":"crates.io","name":"rustls","fixedVersion":"0.22.4"},{"ecosystem":"crates.io","name":"rustls","fixedVersion":"0.21.11"},{"ecosystem":"crates.io","name":"rustls","fixedVersion":null}],"fix":{"url":"https://github.com/rustls/rustls/commit/2123576840aa31043a31b0770e6572136fbe0c2d","label":"rustls/rustls@2123576"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/32xxx/CVE-2024-32650.json"},{"type":"ADVISORY","url":"https://github.com/rustls/rustls/security/advisories/GHSA-6g7w-8wpp-frhj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-32650"},{"type":"FIX","url":"https://github.com/rustls/rustls/commit/2123576840aa31043a31b0770e6572136fbe0c2d"},{"type":"FIX","url":"https://github.com/rustls/rustls/commit/6e938bcfe82a9da7a2e1cbf10b928c7eca26426e"},{"type":"FIX","url":"https://github.com/rustls/rustls/commit/f45664fbded03d833dffd806503d3c8becd1b71e"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T18:48:04.634802700Z"}}