Skip to content
VulniPulse
Advisory severityHigh7.5Red Hat Linux

High [CVE-2026-14456] Denial of Service via unbounded memory growth in QUIC server

This high-severity Red Hat Linux advisory covers CVE-2026-14456 affecting Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat Hardened Images.

Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.

CVE-2026-14456 Source published Source updated

VulniPulse record published Record updated

Affected products & platforms
Red Hat LinuxRed Hat Enterprise Linux
Open source advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit.

Impact summary: A remote peer that can make many Initial packets reach the server listener faster than the application accepts connections, can cause the memory allocated to store the per-channel state to grow without any limits, potentially making the QUIC listener unavailable and causing Denial of Service.

CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: The function that handles inbound QUIC packets uses Connection-Id from the packet header to find an existing connection (QUIC channel). If no existing connection is found and the packet type is INITIAL, the function treats the packet as a new connection.

It allocates a new channel object and inserts it into a queue where it waits to be accepted by the local application with SSL_accept(3ossl). The memory occupied by these initial channel objects may grow without bounds if the application is not able to call SSL_accept() frequently enough to serve these inbound connection requests.

The issue is present since OpenSSL 3.5 when the QUIC server implementation was added. The fix introduces a limit for pending connections.

Affected versions

No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.

Official advisory · high-confidence parse· fetched 19 days ago·verify at source

Fixed versions
  • openssl-1:3.5.8-1.el10_2
  • openssl-1:3.5.8-1.el9_8
  • openssl-main-3.5.6-0.5.hum1
  • RHSA-2026:67154
  • RHSA-2026:67165
  • RHSA-2026:56097

Official advisory · high-confidence parse· fetched 19 days ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • Rate-limit or firewall inbound QUIC (UDP 443) traffic at the network level to reduce exposure. If QUIC server functionality is not required, disable it and use TLS over TCP instead. The upstream fix introduces a default limit of 256 pending connections, configurable via SSL_set_value_uint(3ossl).

Official advisory · high-confidence parse· fetched 19 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.