Debian Package Tracker
Register | Log in
Subscribe

rust-quinn-proto

State machine for the QUIC transport protocol - Rust source code

Choose email to subscribe with

general
  • source: rust-quinn-proto (main)
  • version: 0.11.16-1
  • maintainer: Debian Rust Maintainers (archive) (DMD)
  • uploaders: Matthias Geiger [DMD]
  • arch: any
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • oldstable: 0.9.2-2
  • stable: 0.11.9-1
  • testing: 0.11.16-1
  • unstable: 0.11.16-1
versioned links
  • 0.9.2-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 0.11.9-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 0.11.16-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • librust-quinn-proto-dev
action needed
Debci reports failed tests high
  • unstable: neutral (log)
    The tests ran in 0:00:26
    Last run: 2026-05-27T14:07:32.000Z
    Previous status: unknown

  • testing: fail (log)
    The tests ran in 0:07:16
    Last run: 2026-07-31T15:00:06.000Z
    Previous status: unknown

  • stable: pass (log)
    The tests ran in 0:04:37
    Last run: 2026-07-17T23:40:40.000Z
    Previous status: unknown

Created: 2026-07-31 Last update: 2026-08-05 22:32
2 low-priority security issues in trixie low

There are 2 open security issues in trixie.

2 issues left for the package maintainer to handle:
  • CVE-2026-25800: (needs triaging) Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. Starting in version 0.1.0 and prior to version 0.11.15, the `Assembler` component that assembles unordered stream fragments into consecutive chunks of the stream incurs some overhead for non-contiguous fragments. Readers that read from a `RecvStream` in order (through an `AsyncRead` impl for example) will be sensitive to peers that send fragments while leaving out early parts of the stream, and in particular, fragments with many gaps (because these cannot be defragmented). In such a scenario, the receiving connection suffers from high buffer overhead, enabling memory exhaustion. Version 0.11.15 fixes the issue.
  • CVE-2026-31812: (needs triaging) Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. Prior to 0.11.14, a remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable quinn versions by sending a crafted QUIC Initial packet containing malformed quic_transport_parameters. In quinn-proto parsing logic, attacker-controlled varints are decoded with unwrap(), so truncated encodings cause Err(UnexpectedEnd) and panic. This is reachable over the network with a single packet and no prior trust or authentication. This vulnerability is fixed in 0.11.14.

You can find information about how to handle these issues in the security team's documentation.

Created: 2026-03-13 Last update: 2026-08-02 20:32
debian/patches: 6 patches to forward upstream low

Among the 6 debian patches available in version 0.11.16-1 of the package, we noticed the following issues:

  • 6 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2026-07-21 09:20
news
[rss feed]
  • [2026-07-23] rust-quinn-proto 0.11.16-1 MIGRATED to testing (Debian testing watch)
  • [2026-07-20] Accepted rust-quinn-proto 0.11.16-1 (source) into unstable (Matthias Geiger)
  • [2026-03-20] rust-quinn-proto 0.11.14-1 MIGRATED to testing (Debian testing watch)
  • [2026-03-13] Accepted rust-quinn-proto 0.11.14-1 (source) into unstable (kpcyrd) (signed by: Matthias Geiger)
  • [2026-03-03] rust-quinn-proto 0.11.13-1 MIGRATED to testing (Debian testing watch)
  • [2026-02-28] Accepted rust-quinn-proto 0.11.13-1 (source) into unstable (Matthias Geiger)
  • [2025-11-03] rust-quinn-proto 0.11.9-3 MIGRATED to testing (Debian testing watch)
  • [2025-10-31] Accepted rust-quinn-proto 0.11.9-3 (source) into unstable (Peter Michael Green)
  • [2025-10-31] rust-quinn-proto 0.11.9-2 MIGRATED to testing (Debian testing watch)
  • [2025-10-22] Accepted rust-quinn-proto 0.11.9-2 (source) into unstable (Fabian Grünbichler) (signed by: Fabian Gruenbichler)
  • [2025-04-06] rust-quinn-proto 0.11.9-1 MIGRATED to testing (Debian testing watch)
  • [2025-03-08] Accepted rust-quinn-proto 0.11.9-1 (source) into unstable (Maytham Alsudany) (signed by: Peter Michael Green)
  • [2024-01-14] rust-quinn-proto 0.10.6-1 MIGRATED to testing (Debian testing watch)
  • [2024-01-11] Accepted rust-quinn-proto 0.10.6-1 (source) into unstable (Matthias Geiger)
  • [2023-11-13] rust-quinn-proto 0.10.5-2 MIGRATED to testing (Debian testing watch)
  • [2023-11-07] Accepted rust-quinn-proto 0.10.5-2 (source) into unstable (Peter Michael Green)
  • [2023-11-04] Accepted rust-quinn-proto 0.10.5-1 (source) into experimental (Peter Michael Green)
  • [2023-09-06] rust-quinn-proto 0.10.2-1 MIGRATED to testing (Debian testing watch)
  • [2023-08-17] Accepted rust-quinn-proto 0.10.2-1 (source) into unstable (Peter Michael Green)
  • [2023-02-10] rust-quinn-proto 0.9.2-2 MIGRATED to testing (Debian testing watch)
  • [2023-02-08] Accepted rust-quinn-proto 0.9.2-2 (source) into unstable (Matthias Geiger)
  • [2023-02-02] Accepted rust-quinn-proto 0.9.2-1 (amd64 source) into unstable (Debian FTP Masters) (signed by: Reinhard Tartler)
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 0.11.14-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing