NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker along with conditions beyond their control can use a specially crafted HTTP/3 session to reopen a QPACK encoder stream. This may cause a Use-after-Free in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
| Vendor | Product | Versions |
|---|---|---|
| f5 | nginx open source | 1.31.0 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| nginx | nginx plus | cert_advisory | 90% |
| nginx | nginx | cert_advisory | 90% |
Added a detailed technical description of the XRING flaw in XQUIC and noted that there is no patch available.
Updated affected versions to include Nginx Instant Manager and Nginx Ingress Controller, and added new tags related to additional products.
Updated affected versions to include 1.31.1 and added new tags related to heap-based buffer overflow and specific Nginx components.
Updated CVSS score to 9.2, added new CWE-20, and provided a more detailed description of the vulnerability.
Updated severity to CRITICAL and marked exploit availability as true.
Updated severity to CRITICAL, added new CWE-787, and marked exploit availability as true.
Updated description with new details, changed severity to CRITICAL, and added affected version 1.31.1.
Initial creation