{"id":"CVE-2026-54873","title":"Issue summary: QUIC process may keep memory for QUIC packet\nbuffer for much longer period than necessary.\n\nImpact summary: Remote peer can exploit this vulnerability\nby sending maliciously crafted packets, making the local\nQUIC stack to …","summary":"Issue summary: QUIC process may keep memory for QUIC packet\nbuffer for much longer period than necessary.\n\nImpact summary: Remote peer can exploit this vulnerability\nby sending maliciously crafted packets, making the local\nQUIC stack to …","severity":"none","cwe":["CWE-770"],"vendor":"OpenSSL","product":"OpenSSL","affected":["OpenSSL >= 4.0.0 < 4.0.3","OpenSSL >= 3.6.0 < 3.6.5","OpenSSL >= 3.5.0 < 3.5.9","OpenSSL >= 3.4.0 < 3.4.8"],"published":"2026-09-29","updated":"2026-09-29","sourceUpdated":"2026-09-29T16:17:08.763","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-54873","references":[{"url":"https://github.com/openssl/openssl/commit/1f643b8bc735487b500a1f68a7fb3a22d5e38e23","label":"openssl-security@openssl.org"},{"url":"https://github.com/openssl/openssl/commit/279e7ee1392af98785746788168749491c74bd53","label":"openssl-security@openssl.org"},{"url":"https://github.com/openssl/openssl/commit/3ea6213e050e938ecbbf8c4eff32bec2736780eb","label":"openssl-security@openssl.org"},{"url":"https://github.com/openssl/openssl/commit/7127fb10888b49711c63128a09e524c0d2d5d0b2","label":"openssl-security@openssl.org"},{"url":"https://openssl-library.org/news/secadv/20260929.txt","label":"openssl-security@openssl.org"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-29T16:39:33.266Z","slug":"CVE-2026-54873","body":"## Overview\n\nIssue summary: QUIC process may keep memory for QUIC packet\nbuffer for much longer period than necessary.\n\nImpact summary: Remote peer can exploit this vulnerability\nby sending maliciously crafted packets, making the local\nQUIC stack to keep the memory for packet buffers allocated.\nThe time for which the memory remains allocated is entirely\nunder the control of the potentially malicious remote peer.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: To save copy operation from the packet buffer to the\nstream reassemble buffer the QUIC stack leaves the stream data\non the packet buffer waiting to be copied to a buffer provided\nby the local receiving application. The QUIC stack releases\na reference to the packet buffer only after the data are copied\nto the application buffer. This design is more efficient for\nlegitimate data transfers but enables an attacker to allocate a lot\nmore memory than actually required by the data kept in the receiving\nstream buffer.\n\nTo mitigate the vulnerability, the QUIC stack now calculates\nand monitors memory overhead for every stream. The memory overhead\nfor a single stream frame is calculated as a difference between the\nsize of the whole packet that carries the stream frame and the size\nof the stream frame itself. The memory overhead for a single stream\nframe is added to the total (cumulative) memory overhead QUIC stack\nkeeps for each stream. Once the cumulative memory overhead exceeds\n64kB, the QUIC stack moves the stream frame data from the packet\nbuffer to the stream buffer, starting with the next packet received.\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}