When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module and the network infrastructure supports a Maximum Transmission Unit (MTU) of 4096 or greater without fragmentation, undisclosed QUIC packets can cause NGINX worker processes to leak previously freed memory.
2024-05-29T16:15:10.270
2025-01-24T16:20:57.617
Analyzed
CVSSv3.1: 5.3 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | f5 | nginx_open_source | < 1.26.1 | Yes |
Application | f5 | nginx_plus | r30 | Yes |
Application | f5 | nginx_plus | r30 | Yes |
Application | f5 | nginx_plus | r30 | Yes |
Application | f5 | nginx_plus | r31 | Yes |
Application | f5 | nginx_plus | r31 | Yes |
Operating System | fedoraproject | fedora | 39 | Yes |
Operating System | fedoraproject | fedora | 40 | Yes |