Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers

A single wrong variable on one line in XQUIC, Alibaba’s QUIC and HTTP/3 library, lets any remote client crash the server with a short burst of completely legal traffic. There is no patch.

FoxIO researcher Sébastien Féry disclosed the flaw on July 8 and nicknamed it XRING. He says it needs no login and no malformed packets: about 260 bytes of ordinary QPACK traffic takes the server

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

C programmers commit fresh crimes against readability

C programmers commit fresh crimes against readability Source: Hacker News

What is happening to jobs? Separating AI hype from reality

What is happening to jobs? Separating AI hype from reality Source: Hacker News

ARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial Firms

ARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial Firms Cybersecurity researchers have disclosed details of a targeted campaign aimed at South Korean financial organizations that