Database/Kernel, userspace & hypervisor
OpenSSL QUIC server: per-packet credit accounting breaks the RFC 9000 3x amplification limit
Impact
When a QUIC server built on OpenSSL runs with client address validation disabled, it adds the length of the entire received datagram to its unvalidated send credit once per QUIC packet in that datagram. A peer that packs multiple packets into one datagram makes the server believe far more data arrived than did, so the server will emit more than the 3x reply volume the RFC allows before the handshake completes. The consequence is not a compromise of the server: it is that the server becomes a usable amplifier in a spoofed-source DDoS against a third party. For an operator this is an egress and reputation problem on any public QUIC listener in front of the fleet, and it only applies to deployments that turned address validation off.
Who can reach it
A remote attacker able to spoof source addresses toward a QUIC listener that has address validation disabled. No authentication needed; the abuse happens before the handshake completes.
What to do
Update OpenSSL and restart the QUIC-serving daemons. As an immediate mitigation that needs no patch, re-enable client address validation (retry tokens) on the QUIC server, which restores the intended check. No fixed version is stated in this record beyond the advisory and commits.
References
Related entries
- Xen (x86 HVM): x86 HVM I/O port list traversal flawCVE-2026-42487 · Xen (x86 HVM)Unscored
- OpenSSL QUIC: quadratic stream reassembly lets a peer burn CPU with in-window framesCVE-2026-42772 · OpenSSL QUIC stream reassembly (out-of-order frame buffer list)Unscored
- FreeBSD ZFS: 64-to-32-bit size truncation in the heal receive path corrupts kernel memoryCVE-2026-49430 · FreeBSD ZFS ZFS_IOC_RECV_NEW ioctl (heal receive path)Unscored
- FreeBSD ZFS: unprivileged local user can set the internal $hasrecvd metadata flag on a datasetCVE-2026-49431 · FreeBSD ZFS ZFS_IOC_SET_PROP ioctl (zfs-set privilege check)Unscored
- OpenSSL QUIC: peer controls how long packet buffers stay pinned, inflating memory per streamCVE-2026-54873 · OpenSSL QUIC stack (zero-copy packet buffer retention per stream)Unscored
- Xen (grant tables): Type confusion in grant-copy - guest corrupts hypervisor stateCVE-2026-62428 · Xen (grant tables)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.