CVE-2021-23017

HIGH LAB

nginx - Memory Corruption

Title source: llm

Description

A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact.

Exploits (11)

exploitdb WORKING POC
by Mohammed Alshehri · pythonremotemultiple
https://www.exploit-db.com/exploits/50973
nomisec WORKING POC 132 stars
by M507 · poc
https://github.com/M507/CVE-2021-23017-PoC
nomisec WORKING POC 1 stars
by 6lj · poc
https://github.com/6lj/EVIL-CVE-2021-23017-Update-2025
nomisec WORKING POC 1 stars
by z3usx01 · poc
https://github.com/z3usx01/CVE-2021-23017-POC
nomisec WORKING POC 1 stars
by lakshit1212 · poc
https://github.com/lakshit1212/CVE-2021-23017-PoC
nomisec STUB 1 stars
by niandy · poc
https://github.com/niandy/nginx-patch
gitlab SCANNER
by niklasjanz · poc
https://gitlab.com/niklasjanz/omibus-check-for-cve-2021-23017
nomisec SCANNER
by moften · poc
https://github.com/moften/CVE-2021-23017
nomisec WRITEUP
by Cybervixy · poc
https://github.com/Cybervixy/Vulnerability-Management
nomisec WORKING POC
by lukwagoasuman · poc
https://github.com/lukwagoasuman/-home-lukewago-Downloads-CVE-2021-23017-Nginx-1.14
nomisec WORKING POC
by ShivamDey · poc
https://github.com/ShivamDey/CVE-2021-23017

References (14)

Scores

CVSS v3 7.7
EPSS 0.7354
EPSS Percentile 98.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L

Lab Environment

COMMUNITY
Community Lab
docker pull quay.io/kubernetes-ingress-controller/debian-base-amd64:0.1
+6 more repos

Details

CWE
CWE-193
Status published
Products (25)
f5/nginx 0.6.18 - 1.20.1
fedoraproject/fedora 33
fedoraproject/fedora 34
netapp/ontap_select_deploy_administration_utility
openresty/openresty < 1.19.3.2
oracle/blockchain_platform < 21.1.2
oracle/communications_control_plane_monitor 3.4
oracle/communications_control_plane_monitor 4.2
oracle/communications_control_plane_monitor 4.3
oracle/communications_control_plane_monitor 4.4
... and 15 more
Published Jun 01, 2021
Tracked Since Feb 18, 2026