Memory Management Flaw in QUIC Implementation of OpenSSL
CVE-2026-54873
Currently unrated
What is CVE-2026-54873?
An issue exists in the QUIC implementation within OpenSSL where memory for packet buffers can remain allocated longer than necessary. This allows a remote peer to send maliciously crafted packets, potentially leading to excessive memory usage within the local QUIC stack. The design choice to wait for data to be copied to an application buffer before releasing memory references can be exploited to consume more memory than intended. To enhance security, the QUIC stack has been updated to monitor and limit cumulative memory overhead, ensuring efficient memory management during data transfers.
Affected Version(s)
OpenSSL 4.0.0 < 4.0.3
OpenSSL 3.6.0 < 3.6.5
OpenSSL 3.5.0 < 3.5.9