Stack-based buffer overflow in NGINX Plus and NGINX Open Source - CVE-2024-31079
Published: June 4, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error when HTTP/3 requests within the HTTP/3 QUIC module
(ngx_http_v3_module). A remote attacker can send specially crafted requests to the web server, trigger a stack-based buffer overflow and perform a denial of service (DoS) attack.
This attack requires that a request be specifically timed during the connection draining process, which the attacker has no visibility and limited influence over.
Affected software
NGINX Open Source
Sensor Proxy
IBM Watson Discovery for IBM Cloud Pak for Data
How to mitigate CVE-2024-31079
NGINX Open Source - update to 1.26.1
Sensor Proxy - update to 1.4.0
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 4.8.6, 5.0.1