Executive brief
AWS s2n-quic is a QUIC protocol implementation used in AWS services and customer applications. An excessive memory allocation vulnerability could allow an attacker to consume memory resources on systems running the library, potentially causing denial of service and service unavailability.
Technical details
This vulnerability involves excessive memory allocation in s2n-quic, the AWS QUIC protocol implementation. An attacker can exploit the memory allocation flaw through network-based attacks to cause denial of service by exhausting memory resources. The vulnerability is reachable over the network to any system running the affected s2n-quic library. No evidence of active exploitation in the wild has been reported. Patches or mitigations are available from AWS.
Affected products
- AWS s2n-quic
Timeline
- 2026-09-22: disclosed