vulnerability
FreeBSD: VID-0882f019-bd60-11eb-9bdd-8c164567ca3c (CVE-2021-23017): NGINX -- 1-byte memory overwrite in resolver
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 7 | (AV:N/AC:M/Au:N/C:P/I:P/A:P) | May 25, 2021 | Nov 4, 2022 | Dec 10, 2025 |
Severity
7
CVSS
(AV:N/AC:M/Au:N/C:P/I:P/A:P)
Published
May 25, 2021
Added
Nov 4, 2022
Modified
Dec 10, 2025
Description
NGINX team reports: 1-byte memory overwrite might occur during DNS server response processing if the "resolver" directive was used, allowing an attacker who is able to forge UDP packets from the DNS server to cause worker process crash or, potentially, arbitrary code execution.
Solutions
freebsd-upgrade-package-nginxfreebsd-upgrade-package-nginx-devel
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.