PT-2026-81306 · Openssl+3 · Openssl+3

·

CVE-2026-63075

·

Published

2026-08-25

·

Updated

2026-09-02

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenSSL (affected versions not specified)
Description When processing QUIC traffic, the QUIC stack may retain metadata for ACK-only packets for the entire duration of a connection if a peer repeatedly sends ack-eliciting packets without acknowledging the ACK-only responses. A remote peer that completes a QUIC handshake can exploit this by sending numerous PING frames to force the generation of ACK-only packets while withholding acknowledgments for ack-eliciting data. This behavior causes connection-scoped memory growth, which can lead to a Denial of Service through memory exhaustion, particularly during sustained traffic or across many concurrent QUIC connections.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-97938
CVE-2026-63075
OPENSUSE-SU-2026:11623-1
OPENSUSE-SU-2026:21744-1
USN-8678-1

Affected Products

Freebsd
Linuxmint
Openssl
Ubuntu