> USN-8300-1: ngtcp2 vulnerability
[DATE: 25/05/2026 10:58]
[LANGUAGE: EN]
Zou Dikai discovered that ngtcp2 serialized peer transport parameters into
a fixed 1024-byte stack buffer without bounds checking. When qlog was
enabled, a remote attacker could possibly use this issue to execute
arbitrary code.