CVE-2025-24947: Medium severity lsquic vulnerability
A hash collision vulnerability (in the hash table used to manage connections) in LSQUIC (aka LiteSpeed QUIC) before 4.2.0 allows remote attackers to cause a considerable CPU load on the server (a Hash DoS attack) by initiating connections with colliding Source Connection IDs (SCIDs). This is caused by XXH32 usage.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24947?
CVE-2025-24947 is considered a high-severity vulnerability due to its potential to cause significant CPU load on the affected server.
How do I fix CVE-2025-24947?
To fix CVE-2025-24947, upgrade LSQUIC to version 4.2.0 or later, which addresses this vulnerability.
What type of attack is associated with CVE-2025-24947?
CVE-2025-24947 is associated with a Hash DoS attack that can overwhelm the server's CPU resources.
Which versions of LSQUIC are affected by CVE-2025-24947?
CVE-2025-24947 affects LSQUIC versions prior to 4.2.0.
Can CVE-2025-24947 be exploited remotely?
Yes, CVE-2025-24947 can be exploited remotely by attackers initiating connections with colliding Source Connection IDs.