CVE-2024-45402Disclosure(dena / picotls)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch dena picotls systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Picotls is a TLS protocol library that allows users select different crypto backends based on their use case. When parsing a spoofed TLS handshake message, picotls (specifically, bindings within picotls that call the crypto libraries) may attempt to free the same memory twice. This double free occurs during the disposal of multiple objects without any intervening calls to malloc Typically, this triggers the malloc implementation to detect the error and abort the process. However, depending on the internals of malloc and the crypto backend being used, the flaw could potentially lead to a use-after-free scenario, which might allow for arbitrary code execution. The vulnerability is addressed with commit 9b88159ce763d680e4a13b6e8f3171ae923a535d.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-415

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • picotls

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
picotls

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-02: 1Patch / Workaround · 2026-07-02: 1Technical Details · 2026-07-02: 107-02
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • 𝔸𝕟𝕠𝕟𝕪𝕞𝕠𝕦𝕤 ℍ𝕒𝕔𝕜𝕥𝕚𝕧𝕚𝕤𝕥☭⃠🅇@YourAnon_irc
    Disclosure

    Recent QUIC/TLS/HTTP/3 vulnerabilities (e.g., CVE-2024-45397, CVE-2024-45402) expose data privacy & integrity to DoS attacks and access bypasses. Urgent patching is critical. #Cybersecurity #NetSec #Vulnerabilities

    Post summary

    The tweet announces new QUIC/TLS/HTTP/3 CVEs that expose privacy and integrity to DoS and access bypass attacks, and urges urgent patching.

    0000062
    14 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdenapicotls---

Explore more