Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers
A remote client can crash HTTP/3 servers running XQUIC, Alibaba's HTTP/3 and QUIC library. The vulnerability, dubbed XRING, stems from an incorrect size calculation during table resizing within the QPACK header compressi…

