CVE-2024-34161

CVSS V2 None CVSS V3 None
Description
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module and the network infrastructure supports a Maximum Transmission Unit (MTU) of 4096 or greater without fragmentation, undisclosed QUIC packets can cause NGINX worker processes to leak previously freed memory.
Overview
  • CVE ID
  • CVE-2024-34161
  • Assigner
  • f5
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-05-29T16:02:05.696Z
  • Last Modified Date
  • 2024-05-29T16:02:05.696Z
History
Created Old Value New Value Data Type Notes
2024-06-26 14:27:38 Added to TrackCVE