Double free in OpenSSL - CVE-2026-18798
Published: August 26, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to double free in OpenSSL QUIC stack default packet handler when processing a malformed initial packet. A remote attacker can send a specially crafted initial packet to cause a denial of service.
The issue is triggered when channel creation fails after a QRX object is passed into connection creation, such as with a non-compliant INITIAL packet carrying a destination connection ID shorter than 8 bytes.
Affected software
Debian Linux
FreeBSD
openssl (Debian package)
How to mitigate CVE-2026-18798
openssl (Debian package) - update to 3.5.7-1~deb13u2