VYPR
High severity7.5NVD Advisory· Published Mar 15, 2021· Updated Jun 17, 2026

CVE-2021-24029

CVE-2021-24029

Description

A packet of death scenario is possible in mvfst via a specially crafted message during a QUIC session, which causes a crash via a failed assertion. Per QUIC specification, this particular message should be treated as a connection error. This issue affects mvfst versions prior to commit a67083ff4b8dcbb7ee2839da6338032030d712b0 and proxygen versions prior to v2021.03.15.00.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • Facebook/Mvfst3 versions
    cpe:2.3:a:facebook:mvfst:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:facebook:mvfst:*:*:*:*:*:*:*:*range: <2021-03-13
    • (no CPE)range: <a67083ff4b8dcbb7ee2839da6338032030d712b0
    • (no CPE)range: unspecified
  • Facebook/Proxygen3 versions
    cpe:2.3:a:facebook:proxygen:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:facebook:proxygen:*:*:*:*:*:*:*:*range: <2021.03.15.00
    • (no CPE)range: <v2021.03.15.00
    • (no CPE)range: unspecified

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.