BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

XRING bug lets attackers crash XQUIC servers with legal traffic

XRING flaw in Alibaba XQUIC allows remote crash with 260 bytes QPACK traffic.

  • A remote crash vulnerability dubbed XRING affects all versions of Alibaba’s XQUIC library, disclosed July 8.
  • The flaw requires only 260 bytes of legitimate QPACK traffic, no malformed packets or authentication.
  • No patch exists; operators can disable QPACK’s dynamic table or drop HTTP/3 support.
  • The bug is an integer underflow during ring buffer resizing, similar to a recent HAProxy QUIC crash.

On July 8, FoxIO researcher Sébastien Féry disclosed a vulnerability in Alibaba’s XQUIC library that lets any remote client crash a server using only compliant HTTP/3 traffic.

- Advertisement -

The flaw, named XRING, requires no login and no malformed packets; about 260 bytes of ordinary QPACK instructions take down the server process. XQUIC is open-source, so any server embedding it with default QPACK settings is exposed, including Tengine, Alibaba’s Nginx-based web server that fronts Taobao and Alipay.

Every release through v1.9.4 is affected, and as of July 10 there is no fixed release or CVE. Operators can set SETTINGS_QPACK_MAX_TABLE_CAPACITY to 0 or drop HTTP/3 entirely.

The bug lives in how HTTP/3 compresses headers using QPACK. XQUIC stores the table’s bytes in a ring buffer; when the client asks to grow the table, the code incorrectly sizes leftover tail data against the new buffer’s capacity instead of the old one. Consequently, a grow from 64 to 65 bytes with the write cursor near the end causes an overcount of tail bytes, leading to an unsigned integer underflow that wraps to near-maximum and triggers an out-of-bounds memory copy. FoxIO demonstrated a crash but did not test further exploitation.

None of the attack values break QPACK rules; XQUIC advertises a 16 KiB dynamic-table limit by default, and the payload asks for 64 then 65 bytes. A proof of concept is public. XRING is the latest in a string of remote crashes in HTTP/2 and HTTP/3 stacks, following a use-after-free in NGINX’s HTTP/3 module (CVE-2026-42530) and HAProxy’s patched QUIC crashes in February. FoxIO says it emailed Alibaba on April 7 through the project’s security policy, then followed up four more times without an answer before going public.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

US Senate Delays Crypto Clarity Act Vote Until September

The U.S. Senate will not vote on the Clarity Act before its August recess,...

Trump could net big tax windfall from crypto ethics plan

A bipartisan ethics proposal tied to a crypto market structure bill includes a tax-deferral...

Musk’s Terafab: 50x Pentagon, $16.8B, 3,000 jobs

Elon Musk outlined Terafab’s massive scale, saying the Texas semiconductor complex will be 50...

MARA swings to $611M loss despite record Bitcoin production

MARA swung to a net loss of $611.3 million in Q2 2026, driven by...

SEC Bought Airline Ticket Data Without Warrant, Docs Show

The SEC purchased access to a global airline ticketing database with over 1 billion...

Must Read

18 Countries With No Privacy Laws According To UN (List)

Privacy laws are legal frameworks designed to protect personal data from unauthorized access, misuse, or disclosure.Lack of privacy laws can lead to misuse of...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading