Database/Kernel, userspace & hypervisor
OpenSSL: certificate with many relative-name CRL distribution points inflates heap on TLS handshake
Impact
A peer that presents a crafted certificate under the normal ~100 KiB chain size limit can make the receiving side allocate several hundred MiB of resident memory while caching X.509 extensions, and that memory is held for the life of the certificate object rather than freed immediately. A handful of concurrent connections is enough to push a process into OOM. On a GPU fleet this hits anything that terminates TLS or requests client certificates - API gateways, registries, control-plane and scheduler endpoints, monitoring collectors - and the mTLS-heavy internal paths are exactly the ones that ask for client certificates, so the DoS is reachable from a client, not only from a server. The fix defers CRL distribution point processing until a CRL check actually needs it.
Who can reach it
Any TLS peer that can complete enough of a handshake to send a certificate. No authentication needed: an unauthenticated client against a server that solicits client certificates, or a malicious server against an outbound client.
What to do
Update the OpenSSL packages on affected hosts and restart every service linked against the shared library (or rebuild anything statically linked). The published advisory and commits are the only fix information in this record; no fixed version numbers are stated here. Long-lived daemons keep the vulnerable code mapped until restarted, so plan a rolling restart of TLS-terminating services rather than relying on the package update alone.
References
Related entries
- OpenSSL QUIC server: per-packet credit accounting breaks the RFC 9000 3x amplification limitCVE-2026-35191 · OpenSSL QUIC server (unvalidated address amplification credit accounting)Unscored
- Xen (x86 HVM): x86 HVM I/O port list traversal flawCVE-2026-42487 · Xen (x86 HVM)Unscored
- OpenSSL QUIC: quadratic stream reassembly lets a peer burn CPU with in-window framesCVE-2026-42772 · OpenSSL QUIC stream reassembly (out-of-order frame buffer list)Unscored
- FreeBSD ZFS: 64-to-32-bit size truncation in the heal receive path corrupts kernel memoryCVE-2026-49430 · FreeBSD ZFS ZFS_IOC_RECV_NEW ioctl (heal receive path)Unscored
- FreeBSD ZFS: unprivileged local user can set the internal $hasrecvd metadata flag on a datasetCVE-2026-49431 · FreeBSD ZFS ZFS_IOC_SET_PROP ioctl (zfs-set privilege check)Unscored
- OpenSSL QUIC: peer controls how long packet buffers stay pinned, inflating memory per streamCVE-2026-54873 · OpenSSL QUIC stack (zero-copy packet buffer retention per stream)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.