---
id: CVE-2026-54873
title: |-
  Issue summary: QUIC process may keep memory for QUIC packet
  buffer for much longer period than necessary.

  Impact summary: Remote peer can exploit this vulnerability
  by sending maliciously crafted packets, making the local
  QUIC stack to …
summary: |-
  Issue summary: QUIC process may keep memory for QUIC packet
  buffer for much longer period than necessary.

  Impact summary: Remote peer can exploit this vulnerability
  by sending maliciously crafted packets, making the local
  QUIC stack to …
severity: none
cwe:
  - CWE-770
vendor: OpenSSL
product: OpenSSL
affected:
  - OpenSSL >= 4.0.0 < 4.0.3
  - OpenSSL >= 3.6.0 < 3.6.5
  - OpenSSL >= 3.5.0 < 3.5.9
  - OpenSSL >= 3.4.0 < 3.4.8
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T16:17:08.763'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-54873'
references:
  - url: >-
      https://github.com/openssl/openssl/commit/1f643b8bc735487b500a1f68a7fb3a22d5e38e23
    label: openssl-security@openssl.org
  - url: >-
      https://github.com/openssl/openssl/commit/279e7ee1392af98785746788168749491c74bd53
    label: openssl-security@openssl.org
  - url: >-
      https://github.com/openssl/openssl/commit/3ea6213e050e938ecbbf8c4eff32bec2736780eb
    label: openssl-security@openssl.org
  - url: >-
      https://github.com/openssl/openssl/commit/7127fb10888b49711c63128a09e524c0d2d5d0b2
    label: openssl-security@openssl.org
  - url: 'https://openssl-library.org/news/secadv/20260929.txt'
    label: openssl-security@openssl.org
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-29T16:39:33.266Z'
---

## Overview

Issue summary: QUIC process may keep memory for QUIC packet
buffer for much longer period than necessary.

Impact summary: Remote peer can exploit this vulnerability
by sending maliciously crafted packets, making the local
QUIC stack to keep the memory for packet buffers allocated.
The time for which the memory remains allocated is entirely
under the control of the potentially malicious remote peer.

CWE: CWE-770: Allocation of Resources Without Limits or Throttling

Description: To save copy operation from the packet buffer to the
stream reassemble buffer the QUIC stack leaves the stream data
on the packet buffer waiting to be copied to a buffer provided
by the local receiving application. The QUIC stack releases
a reference to the packet buffer only after the data are copied
to the application buffer. This design is more efficient for
legitimate data transfers but enables an attacker to allocate a lot
more memory than actually required by the data kept in the receiving
stream buffer.

To mitigate the vulnerability, the QUIC stack now calculates
and monitors memory overhead for every stream. The memory overhead
for a single stream frame is calculated as a difference between the
size of the whole packet that carries the stream frame and the size
of the stream frame itself. The memory overhead for a single stream
frame is added to the total (cumulative) memory overhead QUIC stack
keeps for each stream. Once the cumulative memory overhead exceeds
64kB, the QUIC stack moves the stream frame data from the packet
buffer to the stream buffer, starting with the next packet received.

FIPS impact: no
The FIPS module is not affected as the QUIC implementation is outside of
the OpenSSL FIPS module boundary.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
