Back

MEDIUM

NGINX HTTP/3 QUIC vulnerability

Published May 29, 2024

Description

When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module and the network infrastructure supports a Maximum Transmission Unit (MTU) of 4096 or greater without fragmentation, undisclosed QUIC packets can cause NGINX worker processes to leak previously freed memory.

Affected products

Remediation

Red Hat statement

This flaw allows an attacker to cause a memory leak. However, the leaked memory is random, can't be controlled by the attacker, and does not include nginx configuration or private keys. For these reasons, this flaw has been rated with a Moderate severity. The nginx package as shipped in Red Hat Enterprise Linux 8, 9 and RHSCL is not affected by this vulnerability because the support for HTTP/3 is not enabled and the vulnerable code was introduced in a later version of nginx.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Metrics

Weaknesses (1)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner f5
Published May 29, 2024
Updated Feb 13, 2025
Reserved May 14, 2024
CISA Vulnrichment
Updated May 29, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date May 29, 2024