CVE-2024-34161

When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module and the network infrastructure supports a Maximum Transmission Unit (MTU) of 4096 or greater without fragmentation, undisclosed QUIC packets can cause NGINX worker processes to leak previously freed memory.
Configurations

No configuration.

History

No history.

Information

Published : 2024-05-29 16:15

Updated : 2024-06-10 18:15


NVD link : CVE-2024-34161

Mitre link : CVE-2024-34161

CVE.ORG link : CVE-2024-34161


JSON object : View

Products Affected

No product.

CWE
CWE-416

Use After Free