GPU VulnDB

Database/Kernel, userspace & hypervisor

OpenSSL QUIC: peer controls how long packet buffers stay pinned, inflating memory per stream

UnscoredCVE-2026-54873Kernel, userspace & hypervisorcurated

Impact

To avoid a copy, the OpenSSL QUIC stack leaves stream data sitting in the original packet buffer and only drops the reference once the local application copies it out. A peer that sends small stream frames inside large packets therefore pins far more memory than the stream data justifies, and controls how long it stays pinned, since release depends on application reads it can stall. Many concurrent streams turn that into sustained memory pressure on the QUIC-terminating process. The fix tracks per-stream overhead (packet size minus frame size) and migrates data into the stream buffer once cumulative overhead passes 64 kB.

Who can reach it

A remote QUIC peer with an established connection. No application-level authentication is required beyond being able to open streams on the listener.

What to do

Update OpenSSL and restart the QUIC-serving daemons; the mitigation is in library code, not configuration. The record names only the advisory and commits, no fixed version. Disabling QUIC on exposed listeners removes the exposure if the patch cannot be rolled yet.

References

Related entries

All Kernel, userspace & hypervisor entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.