Skip to content

⬆️ Update Rust crate rustls to v0.23.45 [SECURITY] - #198

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/crate-rustls-vulnerability
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/crate-rustls-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
rustls dependencies patch 0.23.43 → 0.23.45

Rustls: TLS 1.3 handshake messages incorrectly accepted across encryption level boundaries

GHSA-2mjx-qc3c-rqvc

More information

Details

Rustls accepted TLS 1.3 handshake messages sent at the wrong encryption level when they followed a key-changing message in the same record. The handshake transcript is still authenticated, so a network-position attacker cannot use this to alter or complete a handshake; the practical effect is that a peer could send handshake messages that should be encrypted in plaintext without rustls rejecting the connection.

This issue affects rustls versions 0.23.13 through 0.23.44 inclusive.

Original report
Summary

Rustls (tested version 0.23.44, and it appears still an issue on latest master though I have not tested this) accepts a TLS 1.3 server flight where a plaintext EncryptedExtensions is packed into the same record as the ServerHello.

This is very similar to Go's CVE-2025-61730 fixed in golang/go@5046bdf

Details

It appears Deframer::aligned considers itself aligned as long as all messages remaining in the buffer are complete. Rustls processes the ServerHello, installs the handshake keys, then pulls the complete (plaintext) EncryptedExtensions out of the buffer.

This is insufficient per RFC 8446 section 5.1's

Handshake messages MUST NOT span key changes. Implementations MUST verify that all messages immediately preceding a key change align with a record boundary; if not, then they MUST terminate the connection with an "unexpected_message" alert. Because the ClientHello, EndOfEarlyData, ServerHello, Finished, and KeyUpdate messages can immediately precede a key change, implementations MUST send these messages in alignment with a record boundary.

Impact

An on path attacker can inject plaintext messages that are accepted.

Tool Use Disclosure

This was discovered by a new TLS/DTLS test suite currently under construction. The specific testcase was inspired by the Go CVE. Other tested implementations (Botan, OpenSSL, BoringSSL, Go, wolfSSL) reject this protocol flow. Daybreak Blue reviewed the rustls code to identify probable root cause.

Severity

  • CVSS Score: 5.3 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added dependencies Pull requests that update a dependency file no-stale labels Oct 7, 2026
@renovate
renovate Bot force-pushed the renovate/crate-rustls-vulnerability branch 3 times, most recently from b27a4d3 to 6264d6a Compare October 9, 2026 15:55
@renovate
renovate Bot force-pushed the renovate/crate-rustls-vulnerability branch from 6264d6a to d4e7d0f Compare October 10, 2026 00:34

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file no-stale

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants