High severity7.5NVD Advisory· Published Dec 22, 2023· Updated Jun 17, 2026
CVE-2023-24609
CVE-2023-24609
Description
Matrix SSL 4.x through 4.6.0 and Rambus TLS Toolkit have a length-subtraction integer overflow for Client Hello Pre-Shared Key extension parsing in the TLS 1.3 server. An attacked device calculates an SHA-2 hash over at least 65 KB (in RAM). With a large number of crafted TLS messages, the CPU becomes heavily loaded. This occurs in tls13VerifyBinder and tls13TranscriptHashUpdate.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:rambus:tls_toolkit:-:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:rambus:tls_toolkit:-:*:*:*:*:*:*:*
- (no CPE)
- Matrix/SSLdescription
Patches
Vulnerability mechanics
References
2- www.telekom.com/en/company/data-privacy-and-security/news/advisories-504842nvdExploitThird Party Advisory
- www.rambus.com/security/software-protocols/tls-toolkit/nvdProduct
News mentions
0No linked articles in our index yet.