High [CVE-2026-14456] Denial of Service via unbounded memory growth in QUIC server
This high-severity Red Hat Linux advisory covers CVE-2026-14456 affecting Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat Hardened Images.
Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.
VulniPulse record published Record updated
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit.
Impact summary: A remote peer that can make many Initial packets reach the server listener faster than the application accepts connections, can cause the memory allocated to store the per-channel state to grow without any limits, potentially making the QUIC listener unavailable and causing Denial of Service.
CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: The function that handles inbound QUIC packets uses Connection-Id from the packet header to find an existing connection (QUIC channel). If no existing connection is found and the packet type is INITIAL, the function treats the packet as a new connection.
It allocates a new channel object and inserts it into a queue where it waits to be accepted by the local application with SSL_accept(3ossl). The memory occupied by these initial channel objects may grow without bounds if the application is not able to call SSL_accept() frequently enough to serve these inbound connection requests.
The issue is present since OpenSSL 3.5 when the QUIC server implementation was added. The fix introduces a limit for pending connections.
Affected versions
No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.
Official advisory · high-confidence parse· fetched 19 days ago·verify at source
- openssl-1:3.5.8-1.el10_2
- openssl-1:3.5.8-1.el9_8
- openssl-main-3.5.6-0.5.hum1
- RHSA-2026:67154
- RHSA-2026:67165
- RHSA-2026:56097
Official advisory · high-confidence parse· fetched 19 days ago·verify at source
Mitigation checklist
- Rate-limit or firewall inbound QUIC (UDP 443) traffic at the network level to reduce exposure. If QUIC server functionality is not required, disable it and use TLS over TCP instead. The upstream fix introduces a default limit of 256 pending connections, configurable via SSL_set_value_uint(3ossl).
Official advisory · high-confidence parse· fetched 19 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.