CVE-2026-14456

EUVD-2026-57919
Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes
valid QUIC Initial packets for unknown destination connection IDs, it
can allocate and queue new incoming channels without enforcing any limit.

Impact summary: A remote peer that can make many Initial packets reach the
server listener faster than the application accepts connections, can cause the
memory allocated to store the per-channel state to grow without any limits,
potentially making the QUIC listener unavailable and causing Denial of Service.

CWE: CWE-770: Allocation of Resources Without Limits or Throttling

Description: The function that handles inbound QUIC packets uses
Connection-Id from the packet header to find an existing connection
(QUIC channel). If no existing connection is found and the packet
type is INITIAL, the function treats the packet as a new connection. It
allocates a new channel object and inserts it into a queue where it
waits to be accepted by the local application with SSL_accept(3ossl).
The memory occupied by these initial channel objects may grow
without bounds if the application is not able to call SSL_accept()
frequently enough to serve these inbound connection requests.

The issue is present since OpenSSL 3.5 when the QUIC server implementation
was added.

The fix introduces a limit for pending connections. The default limit is set
to 256 pending connections (waiting to be accepted by the local application).
Applications may change the default by calling SSL_set_value_uint(3ossl).

FIPS impact: no
The FIPS module is not affected as the QUIC implementation is outside of
the OpenSSL FIPS module boundary.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
opensslCNA
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 52.37%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
opensslopenssl
4.0.0 ≤
𝑥
< 4.0.2
CNA
opensslopenssl
3.6.0 ≤
𝑥
< 3.6.4
CNA
opensslopenssl
3.5.0 ≤
𝑥
< 3.5.8
CNA
Debian logo
Debian Releases
Debian Product
Codename
openssl
bookworm
3.0.20-1~deb12u2
fixed
bookworm (security)
3.0.22-1~deb12u1
fixed
bullseye
not-affected
forky
3.6.4-1
fixed
sid
3.6.4-1
fixed
trixie
3.5.7-1~deb13u2
fixed
trixie (security)
3.5.7-1~deb13u2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
openssl
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
not-affected
resolute
Fixed 3.5.5-1ubuntu3.4
released
trusty
not-affected
xenial
not-affected
openssl-fips
jammy
dne
noble
dne
resolute
dne
openssl1.0
bionic
not-affected
jammy
dne
noble
dne
resolute
dne
nodejs
bionic
needs-triage
focal
not-affected
jammy
not-affected
noble
not-affected
resolute
not-affected
trusty
not-affected
xenial
needs-triage
edk2
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
not-affected
resolute
needs-triage
xenial
not-affected
edk2-hwe
jammy
dne
noble
dne
resolute
needs-triage
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libopenssl-3-devel
suse enterprise desktop 15 SP7
3.5.0-150700.5.50.1
fixed
suse enterprise sap 15 SP7
3.5.0-150700.5.50.1
fixed
suse enterprise server 15 SP7
3.5.0-150700.5.50.1
fixed
libopenssl-3-fips-provider
suse enterprise desktop 15 SP7
3.5.0-150700.5.50.1
fixed
suse enterprise sap 15 SP7
3.5.0-150700.5.50.1
fixed
suse enterprise server 15 SP7
3.5.0-150700.5.50.1
fixed
libopenssl-3-fips-provider-32bit
suse enterprise desktop 15 SP7
3.5.0-150700.5.50.1
fixed
suse enterprise sap 15 SP7
3.5.0-150700.5.50.1
fixed
suse enterprise server 15 SP7
3.5.0-150700.5.50.1
fixed
libopenssl3
suse enterprise desktop 15 SP7
3.5.0-150700.5.50.1
fixed
suse enterprise sap 15 SP7
3.5.0-150700.5.50.1
fixed
suse enterprise server 15 SP7
3.5.0-150700.5.50.1
fixed
libopenssl3-32bit
suse enterprise desktop 15 SP7
3.5.0-150700.5.50.1
fixed
suse enterprise sap 15 SP7
3.5.0-150700.5.50.1
fixed
suse enterprise server 15 SP7
3.5.0-150700.5.50.1
fixed
openssl-3
suse enterprise desktop 15 SP7
3.5.0-150700.5.50.1
fixed
suse enterprise sap 15 SP7
3.5.0-150700.5.50.1
fixed
suse enterprise server 15 SP7
3.5.0-150700.5.50.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
openssl
RHEL 9
1:3.5.8-1.el9_8
fixed
openssl-devel
RHEL 9
1:3.5.8-1.el9_8
fixed
openssl-libs
RHEL 9
1:3.5.8-1.el9_8
fixed
openssl-perl
RHEL 9
1:3.5.8-1.el9_8
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
openssl
Amazon Linux 2023
1:3.5.7-2.amzn2023.0.2
fixed
openssl-debuginfo
Amazon Linux 2023
1:3.5.7-2.amzn2023.0.2
fixed
openssl-debugsource
Amazon Linux 2023
1:3.5.7-2.amzn2023.0.2
fixed
openssl-devel
Amazon Linux 2023
1:3.5.7-2.amzn2023.0.2
fixed
openssl-fips-provider-latest
Amazon Linux 2023
1:3.5.7-2.amzn2023.0.2
fixed
openssl-fips-provider-latest-debuginfo
Amazon Linux 2023
1:3.5.7-2.amzn2023.0.2
fixed
openssl-libs
Amazon Linux 2023
1:3.5.7-2.amzn2023.0.2
fixed
openssl-libs-debuginfo
Amazon Linux 2023
1:3.5.7-2.amzn2023.0.2
fixed
openssl-perl
Amazon Linux 2023
1:3.5.7-2.amzn2023.0.2
fixed
openssl-snapsafe-libs
Amazon Linux 2023
1:3.5.7-2.amzn2023.0.2
fixed
openssl-snapsafe-libs-debuginfo
Amazon Linux 2023
1:3.5.7-2.amzn2023.0.2
fixed