Database/Kernel, userspace & hypervisor
OpenSSL QUIC: quadratic stream reassembly lets a peer burn CPU with in-window frames
Impact
OpenSSL keeps received QUIC stream fragments on a doubly-linked list optimised for appends; any fragment that does not follow the current tail triggers a head-to-tail linear scan. A peer that chooses its frame offsets deliberately forces O(n^2) work per stream while staying inside the advertised receive window and sending fully compliant frames, so the cost falls on the server's CPU at very low attacker bandwidth. That is connection-scoped CPU exhaustion against whatever process terminates QUIC - a gateway or proxy in front of inference endpoints - and it is indistinguishable from legitimate out-of-order traffic at the packet level, so rate limits keyed on volume will not catch it.
Who can reach it
Any remote peer that can complete the QUIC handshake, so authentication at the application layer is irrelevant - reaching the QUIC listener is enough.
What to do
Update OpenSSL and restart the QUIC-terminating daemons. No fixed version is given in this record beyond the advisory and the linked commits. If patching must wait, the exposure is limited to processes that actually serve QUIC, so disabling QUIC/HTTP3 on public listeners removes the attack surface at the cost of falling back to TCP.
References
Related entries
- FreeBSD ZFS: 64-to-32-bit size truncation in the heal receive path corrupts kernel memoryCVE-2026-49430 · FreeBSD ZFS ZFS_IOC_RECV_NEW ioctl (heal receive path)Unscored
- FreeBSD ZFS: unprivileged local user can set the internal $hasrecvd metadata flag on a datasetCVE-2026-49431 · FreeBSD ZFS ZFS_IOC_SET_PROP ioctl (zfs-set privilege check)Unscored
- OpenSSL QUIC: peer controls how long packet buffers stay pinned, inflating memory per streamCVE-2026-54873 · OpenSSL QUIC stack (zero-copy packet buffer retention per stream)Unscored
- Xen (grant tables): Type confusion in grant-copy - guest corrupts hypervisor stateCVE-2026-62428 · Xen (grant tables)Unscored
- Xen (grant tables): Grant-table version change racing with other operationsCVE-2026-62435 · Xen (grant tables)Unscored
- OpenSSL: attacker-controlled CMP sender DN reaches ERR_raise_data() as a format string, crashing the clientCVE-2026-63073 · OpenSSL CMP client (ossl_cmp_msg_check_update sender DN handling)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.