Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
News Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers
The Hacker News
1 month ago

Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers

By info@thehackernews.com (The Hacker News)

A single wrong variable on one line in XQUIC, Alibaba's QUIC and HTTP/3 library, lets any remote client crash the server with a short burst of completely legal traffic. There is no patch. FoxIO researcher Sébastien Féry disclosed the flaw on July 8 and nicknamed it XRING. He says it needs no login and no malformed packets: about 260 bytes of ordinary QPACK traffic takes the server

More from The Hacker News

Leaving Threaticon

This link opens an external site that isn't part of the platform.