FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

nginx-devel -- Multiple Vulnerabilities in HTTP/3

Affected packages
1.25.0 <= nginx-devel < 1.25.4

Details

VuXML ID c97a4ecf-cc25-11ee-b0ee-0050569f0b83
Discovery 2024-02-14
Entry 2024-02-15

The nginx development team reports:

When using HTTP/3 a segmentation fault might occur in a worker process while processing a specially crafted QUIC session.

References

CVE Name CVE-2024-24989
CVE Name CVE-2024-24990