Search CVE reports


Toggle filters

1 – 2 of 2 results


CVE-2026-40170

Medium priority
Needs evaluation

ngtcp2 is a C implementation of the IETF QUIC protocol. In versions prior to 1.22.1, ngtcp2_qlog_parameters_set_transport_params() serializes peer transport parameters into a fixed 1024-byte stack buffer without bounds checking....

1 affected package

ngtcp2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ngtcp2 Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-52811

Medium priority
Needs evaluation

The ngtcp2 project is an effort to implement IETF QUIC protocol in C. In affected versions acks are not validated before being written to the qlog leading to a buffer overflow. In `ngtcp2_conn::conn_recv_pkt` for an ACK, there was...

1 affected package

ngtcp2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ngtcp2 Needs evaluation Needs evaluation Needs evaluation Not in release
Show less packages