Change #246399
Category | curl |
Changed by | Stefan Eissing <stefan | @eissing.org>
Changed at | Wed 22 Oct 2025 11:40:47 |
Repository | https://github.com/curl/curl.git |
Project | curl |
Branch | master |
Revision | bb78c45407e9ad5fc1884d3b5fa9a16bde8af3d7 |
Comments
vquic: fix recvmsg loop for max_pkts The parameter `max_pkts` was not checked in the recvmsg() implementation of vquic_recv_packets() as the packter counter was never increased. This led to the loop running until an EAGAIN was encountered. Which, in any real case scenario, does no harm as long as libcurl is ingesting packets faster than a server is able to send them. However on a slow device and a fast network this could happen and allow a denial of serice. Not a real regression as the vulnerable code has never been released. libcurl 8.16.0 does not have this bug. Closes #19186
Changed files
- lib/vquic/vquic.c