CVE-2024-34161: NGINX HTTP/3 QUIC vulnerability
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module and the network infrastructure supports a Maximum Transmission Unit (MTU) of 4096 or greater without fragmentation, undisclosed QUIC packets can cause NGINX worker processes to leak previously freed memory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-34161?
CVE-2024-34161 is considered a memory leak vulnerability that can affect the stability of NGINX when configured with the HTTP/3 QUIC module.
How do I fix CVE-2024-34161?
To mitigate CVE-2024-34161, update NGINX Plus or NGINX OSS to the latest version that does not contain this vulnerability.
Which versions of NGINX are affected by CVE-2024-34161?
CVE-2024-34161 affects NGINX Plus r30 and r31, as well as NGINX OSS versions between 1.25.0 and 1.26.1 inclusive.
What happens if I don't address CVE-2024-34161?
Failing to address CVE-2024-34161 may lead to increased memory usage and potential process crashes due to memory leaks.
Is CVE-2024-34161 a potential exploit for attackers?
While CVE-2024-34161 itself is a memory leak vulnerability, it can be exploited under specific conditions, potentially allowing for denial of service.