Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers

A single wrong variable on one line in XQUIC, Alibaba’s QUIC and HTTP/3 library, lets any remote client crash the server with a short burst of completely legal traffic. There is no patch.

FoxIO researcher Sébastien Féry disclosed the flaw on July 8 and nicknamed it XRING. He says it needs no login and no malformed packets: about 260 bytes of ordinary QPACK traffic takes the server

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Iowa asks OpenAI to keep their bots sandboxed

Iowa asks OpenAI to keep their bots sandboxed Source: Hacker News

Microsoft Patches a Record 570 Security Flaws

Microsoft Patches a Record 570 Security Flaws Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple

The origins of the school system aimed to produce independent, critical thinkers

The origins of the school system aimed to produce independent, critical thinkers Source: Hacker News