Denial of Service Vulnerability in OpenSSL 3.2-3.6 for QUIC Protocol
CVE-2025-15468
What is CVE-2025-15468?
A vulnerability in OpenSSL versions 3.2 to 3.6 associated with the QUIC protocol can lead to a NULL pointer dereference when an unsupported cipher suite is received from a peer. This issue, emerging from the SSL_CIPHER_find() function, causes the application to experience an abnormal termination, resulting in Denial of Service. Affected applications may call SSL_CIPHER_find() during the client_hello_cb callback, exposing them to this risk. Notably, OpenSSL versions 3.0, 1.1.1, and 1.0.2 remain unaffected by this issue.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
OpenSSL 3.6.0 < 3.6.1
OpenSSL 3.5.0 < 3.5.5
OpenSSL 3.4.0 < 3.4.4
References
Timeline
Vulnerability published
Vulnerability Reserved