NGINX HTTP/3 QUIC vulnerability
Published May 29, 2024
5.3
MEDIUMCVSS 3.1
EPSS 0.87%
Description
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module and the network infrastructure supports a Maximum Transmission Unit (MTU) of 4096 or greater without fragmentation, undisclosed QUIC packets can cause NGINX worker processes to leak previously freed memory.
Affected products
-
- Version 1.25.0StatusaffectedConstraints<1.26.1
- Version
-
- Version R30StatusaffectedConstraints<R32
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| F5 | NGINX Open Source | n/a |
| ||||||
| F5 | NGINX Plus | n/a |
|
Configuration 1
- ≥ 1.25.0 · < 1.26.1
- r30
- r30
- r30
- r31
- r31
Configuration 2
- 39
- 40
-
- Version 1.25.0StatusaffectedConstraints<=1.26.0
- Version
-
- Version r30StatusaffectedConstraints<=r31
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| F5 | Nginx | n/a |
| ||||||
| F5 | Nginx Plus | n/a |
|
Red Hat Ansible Automation Platform 1.2
nginx
Not affected
Red Hat Enterprise Linux 10
nginx
Not affected
Red Hat Enterprise Linux 8
nginx:1.22/nginx
Not affected
Red Hat Enterprise Linux 8
nginx:1.24/nginx
Not affected
Red Hat Enterprise Linux 9
nginx
Not affected
Red Hat Enterprise Linux 9
nginx:1.22/nginx
Not affected
Red Hat Enterprise Linux 9
nginx:1.24/nginx
Not affected
Red Hat Software Collections
rh-nginx118-nginx
Not affected
Red Hat Software Collections
rh-nginx120-nginx
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ansible Automation Platform 1.2 | nginx | Not affected | n/a |
| Red Hat Enterprise Linux 10 | nginx | Not affected | n/a |
| Red Hat Enterprise Linux 8 | nginx:1.22/nginx | Not affected | n/a |
| Red Hat Enterprise Linux 8 | nginx:1.24/nginx | Not affected | n/a |
| Red Hat Enterprise Linux 9 | nginx | Not affected | n/a |
| Red Hat Enterprise Linux 9 | nginx:1.22/nginx | Not affected | n/a |
| Red Hat Enterprise Linux 9 | nginx:1.24/nginx | Not affected | n/a |
| Red Hat Software Collections | rh-nginx118-nginx | Not affected | n/a |
| Red Hat Software Collections | rh-nginx120-nginx | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This flaw allows an attacker to cause a memory leak. However, the leaked memory is random, can't be controlled by the attacker, and does not include nginx configuration or private keys. For these reasons, this flaw has been rated with a Moderate severity. The nginx package as shipped in Red Hat Enterprise Linux 8, 9 and RHSCL is not affected by this vulnerability because the support for HTTP/3 is not enabled and the vulnerable code was introduced in a later version of nginx.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed May 29, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2024–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (6 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.87% (0.00867) | 57.22th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.87% (0.00867) | 53.83th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.23% (0.00229) | 43.70th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00045) | 17.70th | v3 (v2023.03.01) |
| Jun 11, 2024 | 0.04% (0.00045) | 15.35th | v3 (v2023.03.01) |
| May 30, 2024 | 0.04% (0.00043) | 8.73th | v3 (v2023.03.01) |
References (8)
- http://www.openwall.com/lists/oss-security/2024/05/30/4 Mailing List
- https://access.redhat.com/security/cve/CVE-2024-34161 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2283926 Issue Tracking
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MLAOKJWDALQZBIV3WKGPJ6T5Z56D3PRD/ Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/R7RPLWC35WHEUFCGKNFG62ESNID25TEZ/ Third Party Advisory
- https://my.f5.com/manage/s/article/K000139627 vendor-advisoryVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-34161
- https://www.cve.org/CVERecord?id=CVE-2024-34161
Change history (0)
No recorded changes yet.