CVE-2024-34161
published 2024-05-29CVE-2024-34161: When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module and the network infrastructure supports a Maximum Transmission Unit (MTU) of 4096 or…
PriorityP427medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.87%
54.6th percentile
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module and the network infrastructure supports a Maximum Transmission Unit (MTU) of 4096 or greater without fragmentation, undisclosed QUIC packets can cause NGINX worker processes to leak previously freed memory.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nginx | < nginx 1.26.0-2 (forky) | nginx 1.26.0-2 (forky) |
| f5 | nginx | >= 0 < 1.26.0-2 | 1.26.0-2 |
| f5 | nginx | >= 0 < 1.26.0-2 | 1.26.0-2 |
| f5 | nginx_open_source | — | — |
| f5 | nginx_open_source | >= 1.25.0 < 1.26.1 | 1.26.1 |
| f5 | nginx_plus | — | — |
| f5 | nginx_plus | — | — |
| f5 | nginx_plus | — | — |
| f5 | nginx_plus | >= R30 < R32 | R32 |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
osv5.3MEDIUM
vendor_debian5.3LOW
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
nginx: undisclosed QUIC packets can cause NGINX worker processes to leak previously freed memory
vendor_redhat·2024-05-29·CVSS 5.3
CVE-2024-34161 [MEDIUM] CWE-416 nginx: undisclosed QUIC packets can cause NGINX worker processes to leak previously freed memory
nginx: undisclosed QUIC packets can cause NGINX worker processes to leak previously freed memory
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module and the network infrastructure supports a Maximum Transmission Unit (MTU) of 4096 or greater without fragmentation, undisclosed QUIC packets can cause NGINX worker processes to leak previously freed memory.
A flaw was found in the nginx HTTP/3 implementation. If the network infrastructure supports a Maximum Transmission Unit (MTU) of 4096 or greater without fragmentation, undisclosed QUIC packets can trigger a use-after-free condition, causing worker processes to leak previously freed memory.
Statement: This flaw allows an attacker to cause a memory leak. However, the leaked memory is random, can't be controlled by the
F5
CVE-2024-34161: When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module and the network infrastructure supports a M...
vendor_f5·2024-05-29·CVSS 5.3
CVE-2024-34161 [MEDIUM] CWE-416 CVE-2024-34161: When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module and the network infrastructure supports a M...
CVE-2024-34161: When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module and the network infrastructure supports a M...
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module and the network infrastructure supports a Maximum Transmission Unit (MTU) of 4096 or greater without fragmentation, undisclosed QUIC packets can cause NGINX worker processes to leak previously freed memory.
Affected Products: NGINX Plus, Nginx Open Source
Affected Versions: 1.25.0 - 1.26.1; r30; r31
F5 Advisory Articles: K000139627
F5 References: https://my.f5.com/manage/s/article/K000139627
Debian
CVE-2024-34161: nginx - When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module and th...
vendor_debian·2024·CVSS 5.3
CVE-2024-34161 [MEDIUM] CVE-2024-34161: nginx - When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module and th...
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module and the network infrastructure supports a Maximum Transmission Unit (MTU) of 4096 or greater without fragmentation, undisclosed QUIC packets can cause NGINX worker processes to leak previously freed memory.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 1.26.0-2)
sid: resolved (fixed in 1.26.0-2)
trixie: resolved (fixed in 1.26.0-2)
OSV
CVE-2024-34161: When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module and the network infrastructure supports a Maximum Transmission Unit (MTU) of
osv·2024-05-29·CVSS 5.3
CVE-2024-34161 [MEDIUM] CVE-2024-34161: When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module and the network infrastructure supports a Maximum Transmission Unit (MTU) of
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module and the network infrastructure supports a Maximum Transmission Unit (MTU) of 4096 or greater without fragmentation, undisclosed QUIC packets can cause NGINX worker processes to leak previously freed memory.
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2024/05/30/4https://lists.fedoraproject.org/archives/list/[email protected]/message/MLAOKJWDALQZBIV3WKGPJ6T5Z56D3PRD/https://lists.fedoraproject.org/archives/list/[email protected]/message/R7RPLWC35WHEUFCGKNFG62ESNID25TEZ/https://my.f5.com/manage/s/article/K000139627http://www.openwall.com/lists/oss-security/2024/05/30/4https://lists.fedoraproject.org/archives/list/[email protected]/message/MLAOKJWDALQZBIV3WKGPJ6T5Z56D3PRD/https://lists.fedoraproject.org/archives/list/[email protected]/message/R7RPLWC35WHEUFCGKNFG62ESNID25TEZ/https://my.f5.com/manage/s/article/K000139627
2024-05-29
Published