PT-2026-102648 · Openssl · Openssl
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
OpenSSL (affected versions not specified)
Description
The OpenSSL QUIC server, when configured to skip address validation, incorrectly calculates the unvalidated credit limit. When processing a datagram containing multiple QUIC packets, the server adds the total length of the entire datagram to the credit limit for every individual packet contained within it. This behavior allows a remote attacker to spoof packets and trick the server into believing more data was received than actually occurred, violating the RFC 9000 amplification limit of three times the received data. Consequently, a remote attacker could leverage the server to amplify a Distributed Denial of Service (DDoS) attack.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openssl