摘要:
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module and the network infrastructure supports a Maximum Transmission Unit (MTU) of 4096 or greater without fragmentation, undisclosed QUIC packets can cause NGINX worker processes to leak previously freed memory.
安全等级: Low
公告ID: KylinSec-SA-2024-2569
发布日期: 2024年6月4日
关联CVE: CVE-2024-34161
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module and the network infrastructure supports a Maximum Transmission Unit (MTU) of 4096 or greater without fragmentation, undisclosed QUIC packets can cause NGINX worker processes to leak previously freed memory.
cve名称 | 产品 | 组件 | 是否受影响 |
---|---|---|---|
CVE-2024-34161 | KY3.4-5 | nginx | Unaffected |
CVE-2024-34161 | KY3.5.2 | nginx | Unaffected |
CVE-2024-34161 | V6 | nginx | Unaffected |