
CybersecurityHigh
Code Execution Flaw in ngtcp2 Library
A vulnerability in the ngtcp2 library, used for QUIC/HTTP/3, could allow remote code execution. The flaw involves writing data to a fixed-size buffer without checks. Exploitation requires a non-standard logging configuration (qlog) to be enabled, which reduces the immediate risk for most users.
Ubuntu Security Notices1 min read