Database/Kernel, userspace & hypervisor
OpenSSL QUIC: peer controls how long packet buffers stay pinned, inflating memory per stream
Impact
To avoid a copy, the OpenSSL QUIC stack leaves stream data sitting in the original packet buffer and only drops the reference once the local application copies it out. A peer that sends small stream frames inside large packets therefore pins far more memory than the stream data justifies, and controls how long it stays pinned, since release depends on application reads it can stall. Many concurrent streams turn that into sustained memory pressure on the QUIC-terminating process. The fix tracks per-stream overhead (packet size minus frame size) and migrates data into the stream buffer once cumulative overhead passes 64 kB.
Who can reach it
A remote QUIC peer with an established connection. No application-level authentication is required beyond being able to open streams on the listener.
What to do
Update OpenSSL and restart the QUIC-serving daemons; the mitigation is in library code, not configuration. The record names only the advisory and commits, no fixed version. Disabling QUIC on exposed listeners removes the exposure if the patch cannot be rolled yet.
References
Related entries
- Xen (grant tables): Type confusion in grant-copy - guest corrupts hypervisor stateCVE-2026-62428 · Xen (grant tables)Unscored
- Xen (grant tables): Grant-table version change racing with other operationsCVE-2026-62435 · Xen (grant tables)Unscored
- OpenSSL: attacker-controlled CMP sender DN reaches ERR_raise_data() as a format string, crashing the clientCVE-2026-63073 · OpenSSL CMP client (ossl_cmp_msg_check_update sender DN handling)Unscored
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A NULL pointer dereference in the amdkfd (KFD computeCVE-2026-63882 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)Unscored
- Linux kernel x86: no IBPB flush on BPF JIT memory reuse while Spectre-v2 mitigations are in useCVE-2026-64507 · Linux kernel x86/bugs (IBPB flush on BPF JIT allocation)Unscored
- Linux kernel BPF JIT: reused JIT memory can inherit branch predictions from the program that freed itCVE-2026-64508 · Linux kernel BPF JIT allocator (branch-predictor flush on JIT memory reuse)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.