Asymmetric Resource Consumption (Amplification) in OpenSSL - CVE-2026-54874
Published: August 26, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to asymmetric resource consumption in DTLS record buffering when receiving future-epoch records during a handshake in progress. A remote attacker can send numerous small forged DTLS records claiming to belong to the next epoch to cause a denial of service.
Up to 100 such records may be buffered per connection, retaining around 1.7 megabytes of memory because the implementation keeps the entire read buffer for each buffered record.
Affected software
Debian Linux
FreeBSD
openssl (Debian package)
How to mitigate CVE-2026-54874
openssl (Debian package) - update to 3.5.7-1~deb13u2