CVE-2024-34161

MEDIUM

NGINX OSS >=1.25.0 <1.26.1 and NGINX Plus - Use-After-Free via HTTP/3 QUIC Packet Handling

Title source: llm
STIX 2.1

Description

When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module and the network infrastructure supports a Maximum Transmission Unit (MTU) of 4096 or greater without fragmentation, undisclosed QUIC packets can cause NGINX worker processes to leak previously freed memory.

Scores

CVSS v3 5.3
EPSS 0.0074
EPSS Percentile 73.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-416
Status published
Products (5)
f5/nginx_open_source 1.25.0 - 1.26.1
f5/nginx_plus r30 (3 CPE variants)
f5/nginx_plus r31 (2 CPE variants)
fedoraproject/fedora 39
fedoraproject/fedora 40
Published May 29, 2024
Tracked Since Feb 18, 2026