REDHAT-BUG-2489872: Use After Free
NGINX Open Source has a vulnerability in the ngxhttpv3module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker along with conditions beyond their control can use a specially crafted HTTP/3 session to reopen a QPACK encoder stream. This may cause a Use-after-Free in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2489872?
The severity of REDHAT-BUG-2489872 is high with a score of 7.
What is the risk associated with REDHAT-BUG-2489872?
The risk associated with REDHAT-BUG-2489872 is rated at 33.
How do I fix REDHAT-BUG-2489872?
To fix REDHAT-BUG-2489872, update NGINX Open Source to the latest version that addresses this vulnerability.
What type of vulnerability is REDHAT-BUG-2489872?
REDHAT-BUG-2489872 is classified as a Use After Free vulnerability.
Who is affected by REDHAT-BUG-2489872?
NGINX Open Source users configured to use the HTTP/3 QUIC module are affected by REDHAT-BUG-2489872.