Database/Kernel, userspace & hypervisor
OpenSSL QUIC: unthrottled RETIRE_CONNECTION_ID backlog lets a peer force ~400MB of allocation
Impact
The OpenSSL QUIC stack emits a RETIRE_CONNECTION_ID frame for every NEW_CONNECTION_ID it receives and retires the destination connection ID immediately instead of waiting for the ACK, so the limit on how many connection IDs a peer may issue is never enforced. A peer that floods NEW_CONNECTION_ID frames while withholding ACKs grows the control frame queue until roughly 400MB is allocated for a single connection, depending on ACK delay. On a shared node that is a memory-pressure lever against any QUIC-speaking daemon - an HTTP/3 front end or gateway - and enough of them will bring the OOM killer to a host that also holds GPU workloads. Availability only.
Who can reach it
Any remote peer able to establish a QUIC connection to an OpenSSL-based endpoint. No authentication required. Only deployments that actually use OpenSSL's QUIC implementation are affected.
What to do
Take the fixed OpenSSL release from the 2026-09-29 advisory and restart every QUIC-facing service; the advisory text given here does not name a fixed version number, so check it before scheduling. Disabling QUIC/HTTP/3 on exposed listeners is an effective stopgap. The FIPS module is outside the QUIC code.
References
Related entries
- Linux kernel SUNRPC: gssx decode error paths NULL-deref and leak group_info on the NFS serverCVE-2026-89544 · Linux kernel nfsd/SUNRPC gssx option-array decoder (gss-proxy upcall)High
- Linux kernel nfsd: transports routed to threadless service pools hang the connection indefinitelyCVE-2026-89549 · Linux kernel SUNRPC svc_pool_for_cpu() (nfsd pool-to-CPU routing)High
- Linux kernel nfsd: broken short-write detection writes the next segment at the wrong file offsetCVE-2026-89678 · Linux kernel nfsd_direct_write() (NFS server direct-I/O write path)High
- Linux kernel nfsd: NFSv4 SETATTR with the special ONE stateid NULL-derefs and oopses the serverCVE-2026-89679 · Linux kernel nfsd4_setattr() (NFSv4 delegated timestamp attributes)High
- Linux kernel nfsd: each failed inter-server COPY leaks an nfsd_file, pinning inode and mountCVE-2026-89680 · Linux kernel nfsd4_copy() (inter-server COPY setup error path)High
- Linux kernel nfsd: race between cpntf publish and OFFLOAD_CANCEL oopses on an uninitialised list headCVE-2026-89684 · Linux kernel nfsd nfs4_alloc_init_cpntf_state() (server-to-server copy stateid IDR)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.