vulnerability
Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers
High
Summary
A remote client can crash HTTP/3 servers running XQUIC, Alibaba's HTTP/3 and QUIC library. The vulnerability, dubbed XRING, stems from an incorrect size calculation during table resizing within the QPACK header compression mechanism. No patch is available, and the issue affects all versions through v1.9.4. While no exploitation has been reported, the vulnerability has existed since XQUIC's initial release in January 2022.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
