[From nobody Tue Aug 25 21:31:08 2026
Received: (at submit) by bugs.debian.org; 17 Aug 2026 06:38:52 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
 (2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-9.9 required=4.0 tests=BAYES_00, FOURLA,
 FROMDEVELOPER, 
 NO_RELAYS,XMAILER_REPORTBUG autolearn=ham autolearn_force=no
 version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 21; hammy, 150; neutral, 112; spammy,
 0. spammytokens: hammytokens:0.000-+--XDebbugsCc,
 0.000-+--X-Debbugs-Cc, 0.000-+--H*F:U*carnil, 0.000-+--H*Ad:N*Bug,
 0.000-+--HTo:N*Debian
Return-path: &lt;carnil@debian.org&gt;
Received: via submission by buxtehude.debian.org with esmtp (Exim 4.96)
 (envelope-from &lt;carnil@debian.org&gt;) id 1wvqzi-00C6xL-1Y
 for submit@bugs.debian.org; Mon, 17 Aug 2026 06:38:52 +0000
Content-Type: text/plain; charset=&quot;us-ascii&quot;
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: Salvatore Bonaccorso &lt;carnil@debian.org&gt;
To: Debian Bug Tracking System &lt;submit@bugs.debian.org&gt;
Subject: openssl: CVE-2026-14456
Message-ID: &lt;178694872347.2462236.5198554865542507031.reportbug@elende.valinor.li&gt;
X-Mailer: reportbug 13.2.0+nmu1
Date: Mon, 17 Aug 2026 08:38:43 +0200
Delivered-To: submit@bugs.debian.org

Source: openssl
Version: 3.6.3-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: carnil@debian.org, Debian Security Team &lt;team@security.debian.org&gt;

Hi,

The following vulnerability was published for openssl.

CVE-2026-14456[0]:
| Issue summary: When an OpenSSL QUIC server (Listener SSL object)
| processes valid QUIC Initial packets for unknown destination
| connection IDs, it can allocate and queue new incoming channels
| without enforcing any limit.  Impact summary: A remote peer that can
| make many Initial packets reach the server listener faster than the
| application accepts connections, can cause the memory allocated to
| store the per-channel state to grow without any limits, potentially
| making the QUIC listener unavailable and causing Denial of Service.
| CWE: CWE-770: Allocation of Resources Without Limits or Throttling
| Description: The function that handles inbound QUIC packets uses
| Connection-Id from the packet header to find an existing connection
| (QUIC channel). If no existing connection is found and the packet
| type is INITIAL, the function treats the packet as a new connection.
| It allocates a new channel object and inserts it into a queue where
| it waits to be accepted by the local application with
| SSL_accept(3ossl). The memory occupied by these initial channel
| objects may grow without bounds if the application is not able to
| call SSL_accept() frequently enough to serve these inbound
| connection requests.  The issue is present since OpenSSL 3.5 when
| the QUIC server implementation was added.  The fix introduces a
| limit for pending connections. The default limit is set to 256
| pending connections (waiting to be accepted by the local
| application). Applications may change the default by calling
| SSL_set_value_uint(3ossl).  FIPS impact: no The FIPS module is not
| affected as the QUIC implementation is outside of the OpenSSL FIPS
| module boundary.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities &amp; Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-14456
    https://www.cve.org/CVERecord?id=CVE-2026-14456
[1] https://openssl-library.org/news/secadv/20260813.txt

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore
]