CVE-2024-31079

Name
CVE-2024-31079
Description
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate or causeĀ other potential impact. This attack requires that a request be specifically timed during the connection draining process, which the attacker has no visibility and limited influence over.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
vendor-advisory https://my.f5.com/manage/s/article/K000139611
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/R7RPLWC35WHEUFCGKNFG62ESNID25TEZ/
http://www.openwall.com/lists/oss-security/2024/05/30/4
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MLAOKJWDALQZBIV3WKGPJ6T5Z56D3PRD/

Match rules

CPE URI Source package Min version Max version
nginx-open-source >= 1.25.0 < 1.26.1
nginx-plus >= R30 < R32
cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:* nginx_open_source >= 1.25.0 < 1.26.1
cpe:2.3:a:f5:nginx_plus:r30:-:*:*:*:*:*:* nginx_plus == None == r30
cpe:2.3:a:f5:nginx_plus:r31:-:*:*:*:*:*:* nginx_plus == None == r31

Vulnerable and fixed packages

Source package Branch Version Maintainer Status