When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module and the network infrastructure supports a Maximum Transmission Unit (MTU) of 4096 or greater without fragmentation, undisclosed QUIC packets can cause NGINX worker processes to leak previously freed memory.
{
"unresolved_ranges": [
{
"vendor_product": "f5:nginx_plus",
"extracted_events": [
{
"last_affected": "r30-NA"
},
{
"last_affected": "r30-p1"
},
{
"last_affected": "r30-p2"
},
{
"last_affected": "r31-NA"
},
{
"last_affected": "r31-p1"
}
],
"source": "CPE_STRING",
"cpes": [
"cpe:2.3:a:f5:nginx_plus:r30:-:*:*:*:*:*:*",
"cpe:2.3:a:f5:nginx_plus:r30:p1:*:*:*:*:*:*",
"cpe:2.3:a:f5:nginx_plus:r30:p2:*:*:*:*:*:*",
"cpe:2.3:a:f5:nginx_plus:r31:-:*:*:*:*:*:*",
"cpe:2.3:a:f5:nginx_plus:r31:p1:*:*:*:*:*:*"
]
},
{
"vendor_product": "fedoraproject:fedora",
"extracted_events": [
{
"last_affected": "39"
},
{
"last_affected": "40"
}
],
"source": "CPE_STRING",
"cpes": [
"cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*",
"cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*"
]
}
]
}