CVE-2026-40170
ngtcp2 ngtcp2, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9 취약점
ngtcp2 is a C implementation of the IETF QUIC protocol. In versions prior to 1.22.1, ngtcp2_qlog_parameters_set_transport_params() serializes peer transport parameters into a fixed 1024-byte stack buffer without bounds checking. When qlog is enabled, a remote peer can send sufficiently large transport parameters during the QUIC handshake to cause writes beyond the buffer boundary, resulting in a stack buffer overflow. This affects deployments that enable the qlog callback and process untrusted peer transport parameters. This issue has been fixed in version 1.22.1. If developers are unable t...
- 대응 우선순위
- 점검
- CVSS
- 7.5
- EPSS
- 0.78% 백분위 52.3% · 2026.08.04 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.04.17