Inefficient Algorithmic Complexity in OpenSSL - CVE-2026-42772
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to inefficient algorithmic complexity in QUIC stream fragment reassembly when handling out-of-order stream fragments. A remote user can manipulate stream fragment offsets to cause a denial of service.
Exploitation requires completion of the QUIC handshake and can use compliant STREAM frames within the advertised receive window.
Affected software
Debian Linux
openssl (Debian package)
How to mitigate CVE-2026-42772
openssl (Debian package) - update to 3.5.7-1~deb13u3