Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
ngtcp2 could be made to run programs as your login if it received specially crafted network traffic when qlog was enabled.. ========================================================================== Ubuntu Security Notice USN-8300-1 May 25, 2026 ngtcp2 vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: ngtcp2 could be made to run programs as your login if it received specially crafted network traffic when qlog was enabled. Software Description: - ngtcp2: RFC9000 QUIC protocol implementation Details: Zou Dikai discovered that ngtcp2 serialized peer transport parameters into a fixed 1024-byte stack buffer without bounds checking. When qlog was enabled, a remote attacker could possibly use this issue to execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS libngtcp2-16 1.16.0-1ubuntu0.1 libngtcp2-crypto-gnutls-dev 1.16.0-1ubuntu0.1 libngtcp2-crypto-gnutls8 1.16.0-1ubuntu0.1 libngtcp2-crypto-ossl-dev 1.16.0-1ubuntu0.1 libngtcp2-crypto-ossl0 1.16.0-1ubuntu0.1 libngtcp2-dev 1.16.0-1ubuntu0.1 Ubuntu 25.10 libngtcp2-16 1.11.0-1+deb13u1build0.25.10.1 libngtcp2-crypto-gnutls-dev 1.11.0-1+deb13u1build0.25.10.1 libngtcp2-crypto-gnutls8 1.11.0-1+deb13u1build0.25.10.1 libngtcp2-dev 1.11.0-1+deb13u1build0.25.10.1 ngtcp2-client 1.11.0-1+deb13u1build0.25.10.1 ngtcp2-server 1.11.0-1+deb13u1build0.25.10.1 Ubuntu 24.04 LTS libngtcp2-9 0.12.1+dfsg-1+deb12u1build0.24.04.1 libngtcp2-crypto-gnutls-dev 0.12.1+dfsg-1+deb12u1build0.24.04.1 libngtcp2-crypto-gnutls2 0.12.1+dfsg-1+deb12u1build0.24.04.1 libngtcp2-dev 0.12.1+dfsg-1+deb12u1build0.24.04.1 ngtcp2-client 0.12.1+dfsg-1+deb12u1build0.24.04.1 ngtcp2-server 0.12.1+dfsg-1+deb12u1build0.24.04.1 Ubuntu 22.04 LTS libngtcp2-0 0.1.0+dfsg-1ubuntu0.1~esm1 Available with Ubuntu Pro libngtcp2-crypto-gnutls-dev 0.1.0+dfsg-1ubuntu0.1~esm1 Available with Ubuntu Pro libngtcp2-crypto-gnutls0 0.1.0+dfsg-1ubuntu0.1~esm1 Available with Ubuntu Pro libngtcp2-dev 0.1.0+dfsg-1ubuntu0.1~esm1 Available with Ubuntu Pro ngtcp2-client 0.1.0+dfsg-1ubuntu0.1~esm1 Available with Ubuntu Pro ngtcp2-server 0.1.0+dfsg-1ubuntu0.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8300-1 CVE-2026-40170 Package Information: https://launchpad.net/ubuntu/+source/ngtcp2/1.16.0-1ubuntu0.1 https://launchpad.net/ubuntu/+source/ngtcp2/1.11.0-1+deb13u1build0.25.10.1 https://launchpad.net/ubuntu/+source/ngtcp2/0.12.1+dfsg-1+deb12u1build0.24.04.1 . ngtcp2 could run programs as your login through specially crafted traffic when qlog enabled in Ubuntu releases.. ngtcp2 security. . Severity: Critical. LinuxSecurity.com Team
Update to 1.22.1 (rhbz#2452790) Fixes CVE-2026-40170. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-705eb9cf95 2026-04-28 01:29:45.334770+00:00 -------------------------------------------------------------------------------- Name : ngtcp2 Product : Fedora 44 Version : 1.22.1 Release : 1.fc44 URL : https://github.com/ngtcp2/ngtcp2 Summary : Implementation of RFC 9000 QUIC protocol Description : "Call it TCP/2. One More Time." ngtcp2 project is an effort to implement RFC9000 QUIC protocol. -------------------------------------------------------------------------------- Update Information: Update to 1.22.1 (rhbz#2452790) Fixes CVE-2026-40170 -------------------------------------------------------------------------------- ChangeLog: * Mon Apr 20 2026 Petr Men\u0161k - 1.22.1-1 - Update to 1.22.1 (rhbz#2452790) - Fixes CVE-2026-40170 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2452790 - ngtcp2-1.22.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2452790 [ 2 ] Bug #2459283 - CVE-2026-40170 ngtcp2: ngtcp2: Denial of service via stack buffer overflow during QUIC handshake [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2459283 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-705eb9cf95' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Fedora 44 ngtcp2 1.22.1 update fixes CVE-2026-40170 critical buffer overflow issue..ngtcp2 buffer overflow update Fedora critical. . Severity: Critical. LinuxSecurity.com Team
Update to 1.22.1 (rhbz#2452790) Fixes CVE-2026-40170. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-a0f25484e9 2026-04-28 00:55:52.209310+00:00 -------------------------------------------------------------------------------- Name : ngtcp2 Product : Fedora 43 Version : 1.22.1 Release : 1.fc43 URL : https://github.com/ngtcp2/ngtcp2 Summary : Implementation of RFC 9000 QUIC protocol Description : "Call it TCP/2. One More Time." ngtcp2 project is an effort to implement RFC9000 QUIC protocol. -------------------------------------------------------------------------------- Update Information: Update to 1.22.1 (rhbz#2452790) Fixes CVE-2026-40170 -------------------------------------------------------------------------------- ChangeLog: * Mon Apr 20 2026 Petr Men\u0161k - 1.22.1-1 - Update to 1.22.1 (rhbz#2452790) - Fixes CVE-2026-40170 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2452790 - ngtcp2-1.22.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2452790 [ 2 ] Bug #2459283 - CVE-2026-40170 ngtcp2: ngtcp2: Denial of service via stack buffer overflow during QUIC handshake [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2459283 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-a0f25484e9' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Fedora 43 updates ngtcp2 to 1.22.1 addressing critical buffer overflow issue in QUIChandshake.. Fedora 43,nqtcp2 update,CVE-2026-40170,buffer overflow. . Severity: Critical. LinuxSecurity.com Team
Zou Dikai discovered a buffer overflow in ngtcp2, a QUIC protocol library. For the oldstable distribution (bookworm), this problem has been fixed in version 0.12.1+dfsg-1+deb12u1. For the stable distribution (trixie), this problem has been fixed in version 1.11.0-1+deb13u1.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6222-1
Get the latest Linux and open source security news straight to your inbox.