Описание
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate.
A flaw was found in the nginx HTTP/3 implementation. This issue may allow an attacker using a specially crafted QUIC session to trigger a NULL pointer dereference error, causing worker processes to crash and lead to a denial of service.
Отчет
As this flaw allows a remote attacker to cause a denial of service, it has been rated with an important severity. The nginx package as shipped in Red Hat Enterprise Linux 8, 9 and RHSCL is not affected by this vulnerability because the support for HTTP/3 is not enabled and the vulnerable code was introduced in a later version of nginx.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Ansible Automation Platform 1.2 | nginx | Not affected | ||
Red Hat Enterprise Linux 8 | nginx:1.22/nginx | Not affected | ||
Red Hat Enterprise Linux 8 | nginx:1.24/nginx | Not affected | ||
Red Hat Enterprise Linux 9 | nginx | Not affected | ||
Red Hat Enterprise Linux 9 | nginx:1.22/nginx | Not affected | ||
Red Hat Enterprise Linux 9 | nginx:1.24/nginx | Not affected | ||
Red Hat Software Collections | rh-nginx118-nginx | Not affected | ||
Red Hat Software Collections | rh-nginx120-nginx | Not affected |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate.
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate.
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC mod ...
Уязвимость модуля HTTP/3 QUIC (ngx_http_v3_module) веб-серверов NGINX Plus и NGINX OSS, позволяющая нарушителю вызвать отказ в обслуживании
7.5 High
CVSS3