Your message dated Tue, 25 Aug 2026 20:29:11 +0000
with message-id <[email protected]>
and subject line Bug#1144615: fixed in openssl 3.6.4-1
has caused the Debian Bug report #1144615,
regarding openssl: CVE-2026-14456
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1144615: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1144615
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: openssl
Version: 3.6.3-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for openssl.

CVE-2026-14456[0]:
| Issue summary: When an OpenSSL QUIC server (Listener SSL object)
| processes valid QUIC Initial packets for unknown destination
| connection IDs, it can allocate and queue new incoming channels
| without enforcing any limit.  Impact summary: A remote peer that can
| make many Initial packets reach the server listener faster than the
| application accepts connections, can cause the memory allocated to
| store the per-channel state to grow without any limits, potentially
| making the QUIC listener unavailable and causing Denial of Service.
| CWE: CWE-770: Allocation of Resources Without Limits or Throttling
| Description: The function that handles inbound QUIC packets uses
| Connection-Id from the packet header to find an existing connection
| (QUIC channel). If no existing connection is found and the packet
| type is INITIAL, the function treats the packet as a new connection.
| It allocates a new channel object and inserts it into a queue where
| it waits to be accepted by the local application with
| SSL_accept(3ossl). The memory occupied by these initial channel
| objects may grow without bounds if the application is not able to
| call SSL_accept() frequently enough to serve these inbound
| connection requests.  The issue is present since OpenSSL 3.5 when
| the QUIC server implementation was added.  The fix introduces a
| limit for pending connections. The default limit is set to 256
| pending connections (waiting to be accepted by the local
| application). Applications may change the default by calling
| SSL_set_value_uint(3ossl).  FIPS impact: no The FIPS module is not
| affected as the QUIC implementation is outside of the OpenSSL FIPS
| module boundary.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-14456
    https://www.cve.org/CVERecord?id=CVE-2026-14456
[1] https://openssl-library.org/news/secadv/20260813.txt

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: openssl
Source-Version: 3.6.4-1
Done: Sebastian Andrzej Siewior <[email protected]>

We believe that the bug you reported is fixed in the latest version of
openssl, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Sebastian Andrzej Siewior <[email protected]> (supplier of updated 
openssl package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 25 Aug 2026 20:40:24 +0200
Source: openssl
Architecture: source
Version: 3.6.4-1
Distribution: unstable
Urgency: medium
Maintainer: Debian OpenSSL Team <[email protected]>
Changed-By: Sebastian Andrzej Siewior <[email protected]>
Closes: 1143841 1144615 1145172
Changes:
 openssl (3.6.4-1) unstable; urgency=medium
 .
   * Import 3.6.4
     - CVE-2026-18798 ("QUIC Server May Trigger Double Free When Processing
       INITIAL Packet")
     - CVE-2026-63072 ("Heap Buffer Overflow in CMS Key Unwrapping")
     - CVE-2026-63076 ("Invalid Pointer Dereference in CMP Server via Crafted
       protectionAlg")
     - CVE-2026-14457 ("RPK Server Signature Algorithm Selection Can Dereference
       a Missing Certificate")
     - CVE-2026-54874 ("Excessive Memory Use Buffering DTLS Records for a Future
       Epoch")
     - CVE-2026-63073 ("Untrusted Sender DN Used as Format String in CMP 
Response
       Validation")
     - CVE-2026-63074 ("CMP Indefinite Cache Growth of ExtraCerts")
     - CVE-2026-63075 ("QUIC ACK-only Packet Retention Can Cause Memory
       Exhaustion")
     - CVE-2026-75803 ("AEAD Forgeries with Empty Ciphertext When Using
       EVP_Cipher()") (Closes: #1145172)
     - CVE-2026-14456 ("Unbounded Memory Growth in QUIC Server Incoming Channel
       Queue") (Closes: #1144615)
     - CVE-2026-54876 ("Client-Side Memory Leak in OCSP Response Checking") 
(Closes: #1143841)
Checksums-Sha1:
 d2744582a6895e5259ff20eef8d9cb657b9c1ad2 2675 openssl_3.6.4-1.dsc
 85aed0a4acf51f2e0d448310fd61099acf4d100a 55003802 openssl_3.6.4.orig.tar.gz
 987e36db37d0fcb54cd8a34fffa0259c90fb5cef 931 openssl_3.6.4.orig.tar.gz.asc
 e667314305cb4504a1ab9f9c7c7b28e16ded1e6b 51852 openssl_3.6.4-1.debian.tar.xz
Checksums-Sha256:
 c300906132d616fcce9b704f026fe2b15a83407c1b955914f0f8fe1dbb98b1af 2675 
openssl_3.6.4-1.dsc
 9bffaa1ad1e07b354c21bd3324ec02fa15579f45a7d0494b3e74bc449b7333ef 55003802 
openssl_3.6.4.orig.tar.gz
 2f957d2a61971714d256a6ed58a1336a687ee19859538514763f880aa89877de 931 
openssl_3.6.4.orig.tar.gz.asc
 79b60079960546d53abe36a93b52c93a965af8ea8c814d59f3865bbb5ebc1371 51852 
openssl_3.6.4-1.debian.tar.xz
Files:
 3fe339af785ae55358a60ea19dd6dd62 2675 utils optional openssl_3.6.4-1.dsc
 f771f53e0ce36d806d64e15f4d3a36d3 55003802 utils optional 
openssl_3.6.4.orig.tar.gz
 92607567a7850af08af082a3ff639bd4 931 utils optional 
openssl_3.6.4.orig.tar.gz.asc
 fbf687970996cb670773a19166a0c392 51852 utils optional 
openssl_3.6.4-1.debian.tar.xz

-----BEGIN PGP SIGNATURE-----

iQGzBAEBCgAdFiEEV4kucFIzBRM39v3RBWQfF1cS+lsFAmqN9pwACgkQBWQfF1cS
+luPHgv/TBeXuNXafQCkFy7ncYHsPRS/lXgVjWU0Fzto1xzAJ3LGC7iMuWDex4Y+
5TeW78JTidVw1Yh3g2i/290IJwFgNHPI6gX+l01IFVhRbEX0rhFBCsIZDGLZ9qbf
sqwRxSKTMZYj9oXXV8DKtrx8eExNeixUuEzvQBHwukZ4Ta90uPtPi4okcAYAYDkz
+to8+gUc6KJNW1BCFUDpC7AOPDHFNznEx1+NhjsO2Hm9r5LX8ag6r8s8fbtjr6Mb
KPCltrLE8yvHcYRjjL7zLSW5s947dryHDVFyQbZlkfrawXme6bcBIji2jxnyrn2C
r0JNLHknfuZQe3Yrbsn9uJoQsuhR7ObgpE8SUPct36RlBfWEgGFkP57SqZxGx5xn
GyChfVLwMgvwYUn11pfdP5xdthqQDhPG18pLmDnr0f7AuLrPVcInn3QLBYCd1BbN
4P3RJItAH9XPNBehpXd61Sa/ts3BfnqZjFk+piThUbJn3cm46rk3dN2RxpP/ve+p
sX5yqSog
=pgn/
-----END PGP SIGNATURE-----

Attachment: pgpEqLylUGNLM.pgp
Description: PGP signature


--- End Message ---

Reply via email to