[Pkg-openssl-devel] Bug#1144615: openssl: CVE-2026-14456
Salvatore Bonaccorso
carnil at debian.org
Mon Aug 17 07:38:43 BST 2026
Source: openssl
Version: 3.6.3-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: carnil at debian.org, Debian Security Team <team at security.debian.org>
Hi,
The following vulnerability was published for openssl.
CVE-2026-14456[0]:
| Issue summary: When an OpenSSL QUIC server (Listener SSL object)
| processes valid QUIC Initial packets for unknown destination
| connection IDs, it can allocate and queue new incoming channels
| without enforcing any limit. Impact summary: A remote peer that can
| make many Initial packets reach the server listener faster than the
| application accepts connections, can cause the memory allocated to
| store the per-channel state to grow without any limits, potentially
| making the QUIC listener unavailable and causing Denial of Service.
| CWE: CWE-770: Allocation of Resources Without Limits or Throttling
| Description: The function that handles inbound QUIC packets uses
| Connection-Id from the packet header to find an existing connection
| (QUIC channel). If no existing connection is found and the packet
| type is INITIAL, the function treats the packet as a new connection.
| It allocates a new channel object and inserts it into a queue where
| it waits to be accepted by the local application with
| SSL_accept(3ossl). The memory occupied by these initial channel
| objects may grow without bounds if the application is not able to
| call SSL_accept() frequently enough to serve these inbound
| connection requests. The issue is present since OpenSSL 3.5 when
| the QUIC server implementation was added. The fix introduces a
| limit for pending connections. The default limit is set to 256
| pending connections (waiting to be accepted by the local
| application). Applications may change the default by calling
| SSL_set_value_uint(3ossl). FIPS impact: no The FIPS module is not
| affected as the QUIC implementation is outside of the OpenSSL FIPS
| module boundary.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-14456
https://www.cve.org/CVERecord?id=CVE-2026-14456
[1] https://openssl-library.org/news/secadv/20260813.txt
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
More information about the Pkg-openssl-devel
mailing list