CVE-2026-97031
EUVD-2026-9542208.10.2026, 23:17
Multiple ECH outer extension references are not permitted under RFC 9849; previously, a client could send a well-crafted packet that could trigger memory exhaustion in the server process by specifying multiple references. We now reject these as malformed and curb the memory amplification vector as a result.
Awaiting analysis
This vulnerability is currently awaiting analysis.
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| golang |
| ||||||||||||
| golang-1.6 |
| ||||||||||||
| golang-1.8 |
| ||||||||||||
| golang-1.9 |
| ||||||||||||
| golang-1.10 |
| ||||||||||||
| golang-1.13 |
| ||||||||||||
| golang-1.14 |
| ||||||||||||
| golang-1.16 |
| ||||||||||||
| golang-1.17 |
| ||||||||||||
| golang-1.18 |
| ||||||||||||
| golang-1.20 |
| ||||||||||||
| golang-1.21 |
| ||||||||||||
| golang-1.22 |
| ||||||||||||
| golang-1.23 |
| ||||||||||||
| golang-1.24 |
| ||||||||||||
| golang-1.25 |
| ||||||||||||
| golang-1.26 |
| ||||||||||||
| golang-1.27 |
|
Common Weakness Enumeration
Vulnerability Media Exposure