Vulnerability GHSA-5hq8-qhww-jm7q
Summary
libp2p-quic: Remote panic via certificate expiry race during QUIC handshake
Details
Summary
libp2p-quic can panic on an inbound QUIC handshake if a malicious peer presents a valid, short lived libp2p TLS certificate and delays the final TLS 1.3 handshake fragment until the certificate expires.
This is remotely reachable by a network peer and can crash applications exposing a libp2p QUIC listener.
Details
During the TLS handshake, libp2p-tls parses and validates the peer certificate. After Quinn reports handshake completion, libp2p-quic re-parses the same certificate in the post-handshake upgrade path and assumes this cannot fail:
However, libp2p_tls::certificate::parse() re-runs certificate verification on every call, including a wall-clock validity check. A certificate that was valid during the first handshake time parse can expire before the second post-handshake parse, causing the expect(...) to panic.
PoC
A malicious peer can trigger this by:
- Opening a QUIC connection to a libp2p QUIC listener.
- Presenting a valid libp2p TLS certificate with a very short lifetime.
- Allowing the initial handshake-time certificate validation to succeed.
- Withholding the final client handshake fragment packet until after the certificate expires, but before the QUIC handshake timeout elapses.
- The listener completes the handshake and hits the post-handshake certificate re-parse, which panics.
Impact
Remote unauthenticated denial of service. Any application exposing an affected libp2p-quic listener can be crashed by a network peer that performs a valid-looking QUIC/TLS handshake with attacker-controlled timing. No malformed packets are required.