{"id":"CVE-2026-42772","title":"Issue summary: The QUIC stream reassembly algorithm performance deteriorates\nprogressively as packets are arriving out of order","summary":"Issue summary: The QUIC stream reassembly algorithm performance deteriorates\nprogressively as packets are arriving out of order. The worst case has\na quadratic complexity proportional to the number of stream frames kept in\nthe buffer for…","severity":"none","cwe":["CWE-407"],"vendor":"OpenSSL","product":"OpenSSL","affected":["OpenSSL >= 4.0.0 < 4.0.3","OpenSSL >= 3.6.0 < 3.6.5","OpenSSL >= 3.5.0 < 3.5.9","OpenSSL >= 3.4.0 < 3.4.8"],"published":"2026-09-29","updated":"2026-09-29","sourceUpdated":"2026-09-29T16:17:07.640","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-42772","references":[{"url":"https://github.com/openssl/openssl/commit/32d0ed8afe1b8c3e7ece725b44663da3d7087a09","label":"openssl-security@openssl.org"},{"url":"https://github.com/openssl/openssl/commit/ca8402e273af4de5b3f04fa61a0f0c02ce3ae20e","label":"openssl-security@openssl.org"},{"url":"https://github.com/openssl/openssl/commit/eb2becc0a4baea7f3050a247834d0e5c2ebe1773","label":"openssl-security@openssl.org"},{"url":"https://github.com/openssl/openssl/commit/f42ae513bbda513b3c121d54834040ee4a0eae1a","label":"openssl-security@openssl.org"},{"url":"https://openssl-library.org/news/secadv/20260929.txt","label":"openssl-security@openssl.org"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-29T16:39:33.265Z","slug":"CVE-2026-42772","body":"## Overview\n\nIssue summary: The QUIC stream reassembly algorithm performance deteriorates\nprogressively as packets are arriving out of order. The worst case has\na quadratic complexity proportional to the number of stream frames kept in\nthe buffer for the received stream data.\n\nImpact summary: A remote QUIC peer that completes the handshake can create\na connection-scoped CPU pressure and potentially a Denial of Service using\ncompliant STREAM frames inside the advertised receive window, with low\nattacker bandwidth.\n\nCWE: CWE-407: Inefficient Algorithmic Complexity\n\nDescription: OpenSSL manages received QUIC stream fragments using a\ndoubly-linked list. While it optimizes for append operations (at the end of\nthe list), it falls back to a head-to-tail linear search for any fragment\nthat does not immediately follow the current `tail`.\n\nBy manipulating the sequence of offsets, an attacker can force the server\nto perform O(n^2) operations, consuming excessive CPU time for the\nQUIC process.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}