news.mlab.sh
Back to the feed
vulnerability

Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers

High
Image: The Hacker News
Summary

A remote client can crash HTTP/3 servers running XQUIC, Alibaba's HTTP/3 and QUIC library. The vulnerability, dubbed XRING, stems from an incorrect size calculation during table resizing within the QPACK header compression mechanism. No patch is available, and the issue affects all versions through v1.9.4. While no exploitation has been reported, the vulnerability has existed since XQUIC's initial release in January 2022.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.