QUIC STREAM Fragment Metadata DoS
Published Sep 29, 2026
7.5
HIGHCVSS 3.1
EPSS 0.46%
Description
Issue summary: QUIC process may keep memory for QUIC packet buffer for much longer period than necessary.
Impact summary: Remote peer can exploit this vulnerability by sending maliciously crafted packets, making the local QUIC stack to keep the memory for packet buffers allocated. The time for which the memory remains allocated is entirely under the control of the potentially malicious remote peer.
CWE: CWE-770: Allocation of Resources Without Limits or Throttling
Description: To save copy operation from the packet buffer to the stream reassemble buffer the QUIC stack leaves the stream data on the packet buffer waiting to be copied to a buffer provided by the local receiving application. The QUIC stack releases a reference to the packet buffer only after the data are copied to the application buffer. This design is more efficient for legitimate data transfers but enables an attacker to allocate a lot more memory than actually required by the data kept in the receiving stream buffer.
To mitigate the vulnerability, the QUIC stack now calculates and monitors memory overhead for every stream. The memory overhead for a single stream frame is calculated as a difference between the size of the whole packet that carries the stream frame and the size of the stream frame itself. The memory overhead for a single stream frame is added to the total (cumulative) memory overhead QUIC stack keeps for each stream. Once the cumulative memory overhead exceeds 64kB, the QUIC stack moves the stream frame data from the packet buffer to the stream buffer, starting with the next packet received.
FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary.
Affected products
-
- Version 3.4.0StatusaffectedConstraints<3.4.8
- Version 3.5.0StatusaffectedConstraints<3.5.9
- Version 3.6.0StatusaffectedConstraints<3.6.5
- Version 4.0.0StatusaffectedConstraints<4.0.3
- Version
No data.
No data.
Red Hat Hardened Images
openssl-main-3.5.9-0.1.hum1
Fixed · RHSA-2026:74162
Red Hat Hardened Images
openssl3-main-3.5.9-0.1.hum1
Fixed · RHSA-2026:74166
Red Hat Developer Hub
rhdh/rhdh-hub-rhel9
Fix deferred
Red Hat Enterprise Linux 10
edk2
Fix deferred
Red Hat Enterprise Linux 10
openssl
Affected
Red Hat Enterprise Linux 10
shim
Fix deferred
Red Hat Enterprise Linux 10
shim-unsigned-aarch64
Fix deferred
Red Hat Enterprise Linux 10
shim-unsigned-x64
Fix deferred
Red Hat Enterprise Linux 6
openssl
Out of support scope
Red Hat Enterprise Linux 7
openssl
Fix deferred
Red Hat Enterprise Linux 7
ovmf
Fix deferred
Red Hat Enterprise Linux 7
shim-signed
Fix deferred
Red Hat Enterprise Linux 8
compat-openssl10
Fix deferred
Red Hat Enterprise Linux 8
edk2
Fix deferred
Red Hat Enterprise Linux 8
mingw-openssl
Fix deferred
Red Hat Enterprise Linux 8
openssl
Fix deferred
Red Hat Enterprise Linux 8
shim
Fix deferred
Red Hat Enterprise Linux 8
shim-unsigned-aarch64
Fix deferred
Red Hat Enterprise Linux 8
shim-unsigned-x64
Fix deferred
Red Hat Enterprise Linux 9
compat-openssl11
Fix deferred
Red Hat Enterprise Linux 9
edk2
Fix deferred
Red Hat Enterprise Linux 9
openssl
Affected
Red Hat Enterprise Linux 9
shim
Fix deferred
Red Hat Enterprise Linux 9
shim-unsigned-aarch64
Fix deferred
Red Hat Enterprise Linux 9
shim-unsigned-x64
Fix deferred
Red Hat Hardened Images
unbound
Not affected
Red Hat JBoss Core Services
jbcs-httpd24-openssl
Fix deferred
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Fix deferred
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-9
Fix deferred
Red Hat Satellite 6
openvox-agent
Fix deferred
Red Hat Satellite 6
puppet-agent
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Hardened Images | openssl-main-3.5.9-0.1.hum1 | Fixed | RHSA-2026:74162 |
| Red Hat Hardened Images | openssl3-main-3.5.9-0.1.hum1 | Fixed | RHSA-2026:74166 |
| Red Hat Developer Hub | rhdh/rhdh-hub-rhel9 | Fix deferred | n/a |
| Red Hat Enterprise Linux 10 | edk2 | Fix deferred | n/a |
| Red Hat Enterprise Linux 10 | openssl | Affected | n/a |
| Red Hat Enterprise Linux 10 | shim | Fix deferred | n/a |
| Red Hat Enterprise Linux 10 | shim-unsigned-aarch64 | Fix deferred | n/a |
| Red Hat Enterprise Linux 10 | shim-unsigned-x64 | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | openssl | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | openssl | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | ovmf | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | shim-signed | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | compat-openssl10 | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | edk2 | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | mingw-openssl | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | openssl | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | shim | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | shim-unsigned-aarch64 | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | shim-unsigned-x64 | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | compat-openssl11 | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | edk2 | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | openssl | Affected | n/a |
| Red Hat Enterprise Linux 9 | shim | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | shim-unsigned-aarch64 | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | shim-unsigned-x64 | Fix deferred | n/a |
| Red Hat Hardened Images | unbound | Not affected | n/a |
| Red Hat JBoss Core Services | jbcs-httpd24-openssl | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Fix deferred | n/a |
| Red Hat Satellite 6 | openvox-agent | Fix deferred | n/a |
| Red Hat Satellite 6 | puppet-agent | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
1 other source (Red Hat) ▾
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Sep 30, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.46% (0.00462) | 37.88th | v5 (v2026.06.15) |
| Oct 1, 2026 | 0.46% (0.00462) | 37.76th | v5 (v2026.06.15) |
References (9)
- https://access.redhat.com/security/cve/CVE-2026-54873 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2543244 Issue Tracking
- https://github.com/openssl/openssl/commit/1f643b8bc735487b500a1f68a7fb3a22d5e38e23 patch
- https://github.com/openssl/openssl/commit/279e7ee1392af98785746788168749491c74bd53 patch
- https://github.com/openssl/openssl/commit/3ea6213e050e938ecbbf8c4eff32bec2736780eb patch
- https://github.com/openssl/openssl/commit/7127fb10888b49711c63128a09e524c0d2d5d0b2 patch
- https://nvd.nist.gov/vuln/detail/CVE-2026-54873
- https://openssl-library.org/news/secadv/20260929.txt vendor-advisory
- https://www.cve.org/CVERecord?id=CVE-2026-54873
Change history (0)
No recorded changes yet.