Your message dated Wed, 26 Aug 2026 18:47:07 +0000
with message-id <[email protected]>
and subject line Bug#1144615: fixed in openssl 3.5.7-1~deb13u2
has caused the Debian Bug report #1144615,
regarding openssl: CVE-2026-14456
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1144615: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1144615
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: openssl
Version: 3.6.3-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for openssl.
CVE-2026-14456[0]:
| Issue summary: When an OpenSSL QUIC server (Listener SSL object)
| processes valid QUIC Initial packets for unknown destination
| connection IDs, it can allocate and queue new incoming channels
| without enforcing any limit. Impact summary: A remote peer that can
| make many Initial packets reach the server listener faster than the
| application accepts connections, can cause the memory allocated to
| store the per-channel state to grow without any limits, potentially
| making the QUIC listener unavailable and causing Denial of Service.
| CWE: CWE-770: Allocation of Resources Without Limits or Throttling
| Description: The function that handles inbound QUIC packets uses
| Connection-Id from the packet header to find an existing connection
| (QUIC channel). If no existing connection is found and the packet
| type is INITIAL, the function treats the packet as a new connection.
| It allocates a new channel object and inserts it into a queue where
| it waits to be accepted by the local application with
| SSL_accept(3ossl). The memory occupied by these initial channel
| objects may grow without bounds if the application is not able to
| call SSL_accept() frequently enough to serve these inbound
| connection requests. The issue is present since OpenSSL 3.5 when
| the QUIC server implementation was added. The fix introduces a
| limit for pending connections. The default limit is set to 256
| pending connections (waiting to be accepted by the local
| application). Applications may change the default by calling
| SSL_set_value_uint(3ossl). FIPS impact: no The FIPS module is not
| affected as the QUIC implementation is outside of the OpenSSL FIPS
| module boundary.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-14456
https://www.cve.org/CVERecord?id=CVE-2026-14456
[1] https://openssl-library.org/news/secadv/20260813.txt
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: openssl
Source-Version: 3.5.7-1~deb13u2
Done: Sebastian Andrzej Siewior <[email protected]>
We believe that the bug you reported is fixed in the latest version of
openssl, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Sebastian Andrzej Siewior <[email protected]> (supplier of updated
openssl package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Sun, 23 Aug 2026 17:26:22 +0200
Source: openssl
Architecture: source
Version: 3.5.7-1~deb13u2
Distribution: trixie-security
Urgency: medium
Maintainer: Debian OpenSSL Team <[email protected]>
Changed-By: Sebastian Andrzej Siewior <[email protected]>
Closes: 1144615 1145172
Changes:
openssl (3.5.7-1~deb13u2) trixie-security; urgency=medium
.
* CVE-2026-18798 ("QUIC Server May Trigger Double Free When Processing
INITIAL Packet")
* CVE-2026-63072 ("Heap Buffer Overflow in CMS Key Unwrapping")
* CVE-2026-63076 ("Invalid Pointer Dereference in CMP Server via Crafted
protectionAlg")
* CVE-2026-14457 ("RPK Server Signature Algorithm Selection Can Dereference
a Missing Certificate")
* CVE-2026-54874 ("Excessive Memory Use Buffering DTLS Records for a Future
Epoch")
* CVE-2026-63073 ("Untrusted Sender DN Used as Format String in CMP Response
Validation")
* CVE-2026-63074 ("CMP Indefinite Cache Growth of ExtraCerts")
* CVE-2026-63075 ("QUIC ACK-only Packet Retention Can Cause Memory
Exhaustion")
* CVE-2026-75803 ("AEAD Forgeries with Empty Ciphertext When Using
EVP_Cipher()") (Closes: #1145172)
* CVE-2026-14456 ("Unbounded Memory Growth in QUIC Server Incoming Channel
Queue") (Closes: #1144615)
Checksums-Sha1:
3ca57150dc1772933fd41379d021de9a77b83de9 2707 openssl_3.5.7-1~deb13u2.dsc
53d331880fbde8e6fe25870d5325a61201f6264d 53153930 openssl_3.5.7.orig.tar.gz
9408998095f984b36591732286ef1df1ba7ce492 833 openssl_3.5.7.orig.tar.gz.asc
6d1177d59ef985cff4b6baef95ae748ec724af12 74836
openssl_3.5.7-1~deb13u2.debian.tar.xz
Checksums-Sha256:
25904642004d30c5c3da4642a72a7d09f8d9eb6e5ce62dab53c0371114faf8f2 2707
openssl_3.5.7-1~deb13u2.dsc
a8c0d28a529ca480f9f36cf5792e2cd21984552a3c8e4aa11a24aa31aeac98e8 53153930
openssl_3.5.7.orig.tar.gz
d3d082bee3f658c31db53af625eceecf29d777c7010394bed5787ebcc98abdf2 833
openssl_3.5.7.orig.tar.gz.asc
593a47654ead460a3b609503733f80bef552ff0802799d3b47784faacc50809f 74836
openssl_3.5.7-1~deb13u2.debian.tar.xz
Files:
81887cbcbcfffb723ad8f7dcfdcaef70 2707 utils optional
openssl_3.5.7-1~deb13u2.dsc
36608cd5445f708d0c2200aea9682c35 53153930 utils optional
openssl_3.5.7.orig.tar.gz
1550a37dc3382ec617b5fd7d4140b92c 833 utils optional
openssl_3.5.7.orig.tar.gz.asc
1345084467bf31d9c7caf40647744577 74836 utils optional
openssl_3.5.7-1~deb13u2.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQGzBAEBCgAdFiEEV4kucFIzBRM39v3RBWQfF1cS+lsFAmqLE+4ACgkQBWQfF1cS
+ls/WgwAmzlbjcsP6qMq6l4IPgT2VHHG69FRWTJbnELXQ2dnrnknBJR9P/qjq00M
qV302bCH0ryaCYZAfWfYIiYwvTU+pP43iqjpTRKjENh0UDSgx5FiSWn+6i2Jcbl6
QCvx1oJY+1GsGxDoblIoG/hOXwyX8h2T2o3aA+F+rc3A5gJlEm3+GrauE3oM5KRP
UiJCK9yX194VyweZdV3gJmAUzhQ/DhZz2z+a6dMZuaJsTf0ZKtPGL2DLKT7DVHtt
EscEOLKZO96i/6QU4OQDjkLN+RVZ7rsA/uqXqvbnfKqFcEYqOD7WfM/T8ItKi26/
ZvBv23SlhiKbgvRmyJhz5j6F1V9qCrId1dGoGRS2H4cPuxobyFHat1ohbFXJxBxf
RTAc7uFGhgZMebvfFNJj0sc55U1dIqwXQb5ZoyLZPRdUIQYUcYtydoEgA1q6OvnX
qqtDwqjvhSW6P7uvlX9/fFi9k3mE1ihKtBu4rkk3wOUVaOFsBSWIrKjysM0LWqiE
EdZMkxL9
=eCc/
-----END PGP SIGNATURE-----
pgpyXbGY6UymI.pgp
Description: PGP signature
--- End Message ---