CVE-2025-24946

The hash table used to manage connections in picoquic before b80fd3f uses a weak hash function, allowing remote attackers to cause a considerable CPU load on the server (a Hash DoS attack) by initiating connections with colliding Source Connection IDs (SCIDs).
Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) La tabla hash utilizada para administrar las conexiones en Picoquic antes de B80FD3F utiliza una función hash débil, lo que permite a los atacantes remotos causar una carga de CPU considerable en el servidor (un ataque de hash DOS) iniciando conexiones con ID de conexión de origen (SCID).

20 Feb 2025, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-20 03:15

Updated : 2026-04-15 00:35


NVD link : CVE-2025-24946

Mitre link : CVE-2025-24946

CVE.ORG link : CVE-2025-24946


JSON object : View

Products Affected

No product.

CWE
CWE-407

Inefficient Algorithmic Complexity