PT-2026-102651 · Openssl+1 · Openssl+1

·

CVE-2026-54873

·

Published

2026-09-29

·

Updated

2026-10-01

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenSSL (affected versions not specified)
Description The QUIC process may retain memory for packet buffers longer than necessary. A remote peer can exploit this by sending maliciously crafted packets, forcing the local QUIC stack to keep packet buffer memory allocated for a duration controlled by the attacker. This occurs because the QUIC stack leaves stream data on the packet buffer to avoid a copy operation until the data is moved to a buffer provided by the local receiving application. This design allows an attacker to allocate significantly more memory than required by the data in the receiving stream buffer, leading to allocation of resources without limits or throttling.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-105435
AZL-105495
AZL-105576
AZL-105606
AZL-105846
AZL-105867
CVE-2026-54873
USN-8861-1

Affected Products

Openssl
Ubuntu