Debian Package Tracker
Register | Log in
Subscribe

rust-quinn-proto

State machine for the QUIC transport protocol - Rust source code

Choose email to subscribe with

general
  • source: rust-quinn-proto (main)
  • version: 0.11.14-1
  • maintainer: Debian Rust Maintainers (archive) (DMD)
  • uploaders: Matthias Geiger [DMD]
  • arch: any
  • std-ver: 4.7.3
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • oldstable: 0.9.2-2
  • stable: 0.11.9-1
  • testing: 0.11.13-1
  • unstable: 0.11.14-1
versioned links
  • 0.9.2-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 0.11.9-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 0.11.13-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 0.11.14-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • librust-quinn-proto-dev
action needed
1 security issue in trixie high

There is 1 open security issue in trixie.

1 important issue:
  • CVE-2026-31812: Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. Prior to 0.11.14, a remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable quinn versions by sending a crafted QUIC Initial packet containing malformed quic_transport_parameters. In quinn-proto parsing logic, attacker-controlled varints are decoded with unwrap(), so truncated encodings cause Err(UnexpectedEnd) and panic. This is reachable over the network with a single packet and no prior trust or authentication. This vulnerability is fixed in 0.11.14.
Created: 2026-03-13 Last update: 2026-03-14 00:16
1 security issue in forky high

There is 1 open security issue in forky.

1 important issue:
  • CVE-2026-31812: Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. Prior to 0.11.14, a remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable quinn versions by sending a crafted QUIC Initial packet containing malformed quic_transport_parameters. In quinn-proto parsing logic, attacker-controlled varints are decoded with unwrap(), so truncated encodings cause Err(UnexpectedEnd) and panic. This is reachable over the network with a single packet and no prior trust or authentication. This vulnerability is fixed in 0.11.14.
Created: 2026-03-13 Last update: 2026-03-14 00:16
2 security issues in bookworm high

There are 2 open security issues in bookworm.

1 important issue:
  • CVE-2026-31812: Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. Prior to 0.11.14, a remote, unauthenticated attacker can trigger a denial of service in applications using vulnerable quinn versions by sending a crafted QUIC Initial packet containing malformed quic_transport_parameters. In quinn-proto parsing logic, attacker-controlled varints are decoded with unwrap(), so truncated encodings cause Err(UnexpectedEnd) and panic. This is reachable over the network with a single packet and no prior trust or authentication. This vulnerability is fixed in 0.11.14.
1 issue left for the package maintainer to handle:
  • CVE-2023-42805: (needs triaging) quinn-proto is a state machine for the QUIC transport protocol. Prior to versions 0.9.5 and 0.10.5, receiving unknown QUIC frames in a QUIC packet could result in a panic. The problem has been fixed in 0.9.5 and 0.10.5 maintenance releases.

You can find information about how to handle this issue in the security team's documentation.

Created: 2023-09-22 Last update: 2026-03-14 00:16
Failed to analyze the VCS repository. Please troubleshoot and fix the issue. high
vcswatch reports that there is an error with this package's VCS, or the debian/changelog file inside it. Please check the error shown below and try to fix it. You might have to update the VCS URL in the debian/control file to point to the correct repository.

fatal: shallow file has changed since we read it
Created: 2026-03-13 Last update: 2026-03-13 22:04
piuparts found (un)installation error(s) normal
Piuparts stresses package installation, uninstallation, upgrade, ... While doing such tests, one or more errors were found for the following suites:
  • sid - piuparts
You should fix them.
Created: 2026-03-14 Last update: 2026-03-14 00:16
16 open merge requests in Salsa normal
There are 16 open merge requests for this package on Salsa. You should consider reviewing and/or merging these merge requests.
Created: 2025-09-22 Last update: 2026-03-06 10:31
lintian reports 3 warnings normal
Lintian reports 3 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2026-03-01 Last update: 2026-03-01 09:00
debian/patches: 7 patches to forward upstream low

Among the 7 debian patches available in version 0.11.13-1 of the package, we noticed the following issues:

  • 7 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2026-03-01 10:31
testing migrations
  • excuses:
    • Migration status for rust-quinn-proto (0.11.13-1 to 0.11.14-1): BLOCKED: Rejected/violates migration policy/introduces a regression
    • Issues preventing migration:
    • ∙ ∙ Piuparts regression - https://piuparts.debian.org/sid/source/r/rust-quinn-proto.html
    • ∙ ∙ Missing build on riscv64
    • ∙ ∙ Autopkgtest deferred on riscv64: missing arch:riscv64 build
    • ∙ ∙ Autopkgtest for rust-quinn/0.11.9-2: amd64: Pass, arm64: Pass, i386: Pass, ppc64el: Test triggered, s390x: Test triggered
    • ∙ ∙ Autopkgtest for rust-quinn-proto/0.11.14-1: amd64: Pass, arm64: Pass, i386: Pass, ppc64el: Test triggered, s390x: Test triggered
    • ∙ ∙ Lintian check waiting for test results - info
    • ∙ ∙ Too young, only 0 of 5 days old
    • Additional info (not blocking):
    • ∙ ∙ Reproducibility check waiting for results on amd64
    • ∙ ∙ Reproducibility check waiting for results on arm64
    • ∙ ∙ Reproducibility check waiting for results on armhf
    • ∙ ∙ Reproducibility check waiting for results on i386
    • ∙ ∙ Reproducibility check waiting for results on ppc64el
    • Not considered
news
[rss feed]
  • [2026-03-13] Accepted rust-quinn-proto 0.11.14-1 (source) into unstable (kpcyrd) (signed by: Matthias Geiger)
  • [2026-03-03] rust-quinn-proto 0.11.13-1 MIGRATED to testing (Debian testing watch)
  • [2026-02-28] Accepted rust-quinn-proto 0.11.13-1 (source) into unstable (Matthias Geiger)
  • [2025-11-03] rust-quinn-proto 0.11.9-3 MIGRATED to testing (Debian testing watch)
  • [2025-10-31] Accepted rust-quinn-proto 0.11.9-3 (source) into unstable (Peter Michael Green)
  • [2025-10-31] rust-quinn-proto 0.11.9-2 MIGRATED to testing (Debian testing watch)
  • [2025-10-22] Accepted rust-quinn-proto 0.11.9-2 (source) into unstable (Fabian Grünbichler) (signed by: Fabian Gruenbichler)
  • [2025-04-06] rust-quinn-proto 0.11.9-1 MIGRATED to testing (Debian testing watch)
  • [2025-03-08] Accepted rust-quinn-proto 0.11.9-1 (source) into unstable (Maytham Alsudany) (signed by: Peter Michael Green)
  • [2024-01-14] rust-quinn-proto 0.10.6-1 MIGRATED to testing (Debian testing watch)
  • [2024-01-11] Accepted rust-quinn-proto 0.10.6-1 (source) into unstable (Matthias Geiger)
  • [2023-11-13] rust-quinn-proto 0.10.5-2 MIGRATED to testing (Debian testing watch)
  • [2023-11-07] Accepted rust-quinn-proto 0.10.5-2 (source) into unstable (Peter Michael Green)
  • [2023-11-04] Accepted rust-quinn-proto 0.10.5-1 (source) into experimental (Peter Michael Green)
  • [2023-09-06] rust-quinn-proto 0.10.2-1 MIGRATED to testing (Debian testing watch)
  • [2023-08-17] Accepted rust-quinn-proto 0.10.2-1 (source) into unstable (Peter Michael Green)
  • [2023-02-10] rust-quinn-proto 0.9.2-2 MIGRATED to testing (Debian testing watch)
  • [2023-02-08] Accepted rust-quinn-proto 0.9.2-2 (source) into unstable (Matthias Geiger)
  • [2023-02-02] Accepted rust-quinn-proto 0.9.2-1 (amd64 source) into unstable (Debian FTP Masters) (signed by: Reinhard Tartler)
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian (0, 3)
  • buildd: logs, cross
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 0.11.9-3

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing