{"schema_version":"1.7.2","id":"OESA-2026-3579","modified":"2026-08-30T04:18:29Z","published":"2026-08-30T04:18:29Z","upstream":["CVE-2026-14456"],"summary":"openssl security update","details":"OpenSSL is a robust, commercial-grade, and full-featured toolkit for the Transport Layer Security (TLS) and Secure Sockets Layer (SSL) protocols.\r\n\r\nSecurity Fix(es):\n\nIssue summary: When an OpenSSL QUIC server (Listener SSL object) processes\nvalid QUIC Initial packets for unknown destination connection IDs, it\ncan allocate and queue new incoming channels without enforcing any limit.\n\nImpact summary: A remote peer that can make many Initial packets reach the\nserver listener faster than the application accepts connections, can cause the\nmemory allocated to store the per-channel state to grow without any limits,\npotentially making the QUIC listener unavailable and causing Denial of Service.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: The function that handles inbound QUIC packets uses\nConnection-Id from the packet header to find an existing connection\n(QUIC channel). If no existing connection is found and the packet\ntype is INITIAL, the function treats the packet as a new connection. It\nallocates a new channel object and inserts it into a queue where it\nwaits to be accepted by the local application with SSL_accept(3ossl).\nThe memory occupied by these initial channel objects may grow\nwithout bounds if the application is not able to call SSL_accept()\nfrequently enough to serve these inbound connection requests.\n\nThe issue is present since OpenSSL 3.5 when the QUIC server implementation\nwas added.\n\nThe fix introduces a limit for pending connections. The default limit is set\nto 256 pending connections (waiting to be accepted by the local application).\nApplications may change the default by calling SSL_set_value_uint(3ossl).\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary.(CVE-2026-14456)","affected":[{"package":{"ecosystem":"openEuler:24.03-LTS-SP4","name":"openssl","purl":"pkg:rpm/openEuler/openssl&distro=openEuler-24.03-LTS-SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.5.6-5.oe2403sp4"}]}],"ecosystem_specific":{"aarch64":["openssl-3.5.6-5.oe2403sp4.aarch64.rpm","openssl-debuginfo-3.5.6-5.oe2403sp4.aarch64.rpm","openssl-debugsource-3.5.6-5.oe2403sp4.aarch64.rpm","openssl-devel-3.5.6-5.oe2403sp4.aarch64.rpm","openssl-libs-3.5.6-5.oe2403sp4.aarch64.rpm","openssl-perl-3.5.6-5.oe2403sp4.aarch64.rpm"],"noarch":["openssl-help-3.5.6-5.oe2403sp4.noarch.rpm"],"src":["openssl-3.5.6-5.oe2403sp4.src.rpm"],"x86_64":["openssl-3.5.6-5.oe2403sp4.x86_64.rpm","openssl-debuginfo-3.5.6-5.oe2403sp4.x86_64.rpm","openssl-debugsource-3.5.6-5.oe2403sp4.x86_64.rpm","openssl-devel-3.5.6-5.oe2403sp4.x86_64.rpm","openssl-libs-3.5.6-5.oe2403sp4.x86_64.rpm","openssl-perl-3.5.6-5.oe2403sp4.x86_64.rpm"]}}],"references":[{"type":"ADVISORY","url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3579"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-14456"}],"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"database_specific":{"severity":"High"}}
