Количество 14
Количество 14
CVE-2026-40170
ngtcp2 is a C implementation of the IETF QUIC protocol. In versions prior to 1.22.1, ngtcp2_qlog_parameters_set_transport_params() serializes peer transport parameters into a fixed 1024-byte stack buffer without bounds checking. When qlog is enabled, a remote peer can send sufficiently large transport parameters during the QUIC handshake to cause writes beyond the buffer boundary, resulting in a stack buffer overflow. This affects deployments that enable the qlog callback and process untrusted peer transport parameters. This issue has been fixed in version 1.22.1. If developers are unable to immediately upgrade, they can disable the qlog on client.
CVE-2026-40170
ngtcp2 is a C implementation of the IETF QUIC protocol. In versions prior to 1.22.1, ngtcp2_qlog_parameters_set_transport_params() serializes peer transport parameters into a fixed 1024-byte stack buffer without bounds checking. When qlog is enabled, a remote peer can send sufficiently large transport parameters during the QUIC handshake to cause writes beyond the buffer boundary, resulting in a stack buffer overflow. This affects deployments that enable the qlog callback and process untrusted peer transport parameters. This issue has been fixed in version 1.22.1. If developers are unable to immediately upgrade, they can disable the qlog on client.
CVE-2026-40170
ngtcp2 is a C implementation of the IETF QUIC protocol. In versions prior to 1.22.1, ngtcp2_qlog_parameters_set_transport_params() serializes peer transport parameters into a fixed 1024-byte stack buffer without bounds checking. When qlog is enabled, a remote peer can send sufficiently large transport parameters during the QUIC handshake to cause writes beyond the buffer boundary, resulting in a stack buffer overflow. This affects deployments that enable the qlog callback and process untrusted peer transport parameters. This issue has been fixed in version 1.22.1. If developers are unable to immediately upgrade, they can disable the qlog on client.
CVE-2026-40170
ngtcp2 has a qlog transport parameter serialization stack buffer overflow
CVE-2026-40170
ngtcp2 is a C implementation of the IETF QUIC protocol. In versions pr ...
RLSA-2026:25049
Critical: samba security update
RLSA-2026:22963
Critical: samba security update
ELSA-2026-25049
ELSA-2026-25049: samba security update (CRITICAL)
ELSA-2026-22963
ELSA-2026-22963: samba security update (CRITICAL)
SUSE-SU-2026:2695-1
Security update for nodejs22
SUSE-SU-2026:2647-1
Security update for nodejs22
openSUSE-SU-2026:21236-1
Security update for nodejs24
SUSE-SU-2026:2633-1
Security update for nodejs24
openSUSE-SU-2026:21058-1
Security update for nodejs22
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-40170 ngtcp2 is a C implementation of the IETF QUIC protocol. In versions prior to 1.22.1, ngtcp2_qlog_parameters_set_transport_params() serializes peer transport parameters into a fixed 1024-byte stack buffer without bounds checking. When qlog is enabled, a remote peer can send sufficiently large transport parameters during the QUIC handshake to cause writes beyond the buffer boundary, resulting in a stack buffer overflow. This affects deployments that enable the qlog callback and process untrusted peer transport parameters. This issue has been fixed in version 1.22.1. If developers are unable to immediately upgrade, they can disable the qlog on client. | CVSS3: 7.5 | 1% Низкий | 4 месяца назад | |
CVE-2026-40170 ngtcp2 is a C implementation of the IETF QUIC protocol. In versions prior to 1.22.1, ngtcp2_qlog_parameters_set_transport_params() serializes peer transport parameters into a fixed 1024-byte stack buffer without bounds checking. When qlog is enabled, a remote peer can send sufficiently large transport parameters during the QUIC handshake to cause writes beyond the buffer boundary, resulting in a stack buffer overflow. This affects deployments that enable the qlog callback and process untrusted peer transport parameters. This issue has been fixed in version 1.22.1. If developers are unable to immediately upgrade, they can disable the qlog on client. | CVSS3: 7.5 | 1% Низкий | 4 месяца назад | |
CVE-2026-40170 ngtcp2 is a C implementation of the IETF QUIC protocol. In versions prior to 1.22.1, ngtcp2_qlog_parameters_set_transport_params() serializes peer transport parameters into a fixed 1024-byte stack buffer without bounds checking. When qlog is enabled, a remote peer can send sufficiently large transport parameters during the QUIC handshake to cause writes beyond the buffer boundary, resulting in a stack buffer overflow. This affects deployments that enable the qlog callback and process untrusted peer transport parameters. This issue has been fixed in version 1.22.1. If developers are unable to immediately upgrade, they can disable the qlog on client. | CVSS3: 7.5 | 1% Низкий | 4 месяца назад | |
CVE-2026-40170 ngtcp2 has a qlog transport parameter serialization stack buffer overflow | 1% Низкий | 3 месяца назад | ||
CVE-2026-40170 ngtcp2 is a C implementation of the IETF QUIC protocol. In versions pr ... | CVSS3: 7.5 | 1% Низкий | 4 месяца назад | |
RLSA-2026:25049 Critical: samba security update | около 2 месяцев назад | |||
RLSA-2026:22963 Critical: samba security update | около 2 месяцев назад | |||
ELSA-2026-25049 ELSA-2026-25049: samba security update (CRITICAL) | около 1 месяца назад | |||
ELSA-2026-22963 ELSA-2026-22963: samba security update (CRITICAL) | 17 дней назад | |||
SUSE-SU-2026:2695-1 Security update for nodejs22 | около 1 месяца назад | |||
SUSE-SU-2026:2647-1 Security update for nodejs22 | около 1 месяца назад | |||
openSUSE-SU-2026:21236-1 Security update for nodejs24 | 26 дней назад | |||
SUSE-SU-2026:2633-1 Security update for nodejs24 | около 1 месяца назад | |||
openSUSE-SU-2026:21058-1 Security update for nodejs22 | около 1 месяца назад |
Уязвимостей на страницу