PT-2021-3126 · Nginx+9 · Nginx+9
CVE-2021-23017
·
Published
2021-05-25
·
Updated
2026-05-24
CVSS v3.1
7.7
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
nginx versions 1.20.0
Description
A security issue in the nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause a 1-byte memory overwrite, resulting in a worker process crash or potential other impact. The issue is related to an off-by-one heap write vulnerability in the
ngx resolver copy() function.Recommendations
For nginx version 1.20.0, update to a newer version that contains a fix for this issue. As a temporary workaround, consider restricting access to the DNS resolver to minimize the risk of exploitation.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Almalinux
Centos
Linuxmint
Nginx
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu