CVE-2023-53157 Details
Description
The rosenpass crate before 0.2.1 for Rust allows remote attackers to cause a denial of service (panic) via a one-byte UDP packet.
A denial-of-service vulnerability has been identified in the Rosenpass crate for Rust, affecting versions prior to 0.2.1. The issue arises because the crate does not properly validate the size of buffers when decoding messages. This oversight allows remote attackers to cause a panic by sending a one-byte UDP packet. The vulnerability has been addressed in version 0.2.1.
Users can upgrade to Rosenpass version 0.2.1 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 28, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://crates.io/crates/rosenpass | [email protected] | Product |
| https://github.com/advisories/GHSA-6ggr-cwv4-g7qg | [email protected] | Third Party Advisory |
| https://github.com/rosenpass/rosenpass/commit/93439858d1c44294a7b377f775c4fc897a370bb2 | [email protected] | Patch |
| https://rustsec.org/advisories/RUSTSEC-2023-0077.html | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-130 | Improper Handling of Length Parameter Inconsistency | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| rosenpass rosenpass | < 0.2.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 7, 2025 | Initial Analysis | [email protected] |
| Jul 28, 2025 | New CVE Received | [email protected] |