First published: Wed May 29 2024(Updated: )
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module and the network infrastructure supports a Maximum Transmission Unit (MTU) of 4096 or greater without fragmentation, undisclosed QUIC packets can cause NGINX worker processes to leak previously freed memory.
Credit: f5sirt@f5.com
Affected Software | Affected Version | How to fix |
---|---|---|
F5 NGINX Open Source | >=1.25.0<1.26.1 | |
F5 NGINX Plus | =r30 | |
F5 NGINX Plus | =r30-p1 | |
F5 NGINX Plus | =r30-p2 | |
F5 NGINX Plus | =r31 | |
F5 NGINX Plus | =r31-p1 | |
Fedoraproject Fedora | =39 | |
Fedoraproject Fedora | =40 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.