PT-2026-102660 · Openssl · Openssl
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
OpenSSL (affected versions not specified)
Description
A malicious remote peer can flood the local QUIC stack with
NEW CONNECTION ID frames by bypassing the limit check on the number of connection IDs the remote stack can use. The local stack responds to each NEW CONNECTION ID frame by sending a RETIRE CONN ID frame via the Control Frame Queue (CFQ). If the remote peer withholds ACKs, the local stack can be forced to allocate approximately 400MB of memory. This occurs because the stack incorrectly retires the destination CID immediately upon receiving the NEW CONNECTION ID frame, rather than waiting for an ACK for the RETIRE CONNECTION ID frame as required by RFC 9000.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openssl