Incomplete in the CWE catalog · 1 CVE mapped
The product locks a critical resource more times than intended, leading to an unexpected state in the system.
If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.