Inefficient Algorithmic Complexity in OpenSSL - CVE-2026-42772

 

Inefficient Algorithmic Complexity in OpenSSL - CVE-2026-42772

Published: September 30, 2026


Vulnerability identifier: #VU152955
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-42772
CWE-ID: CWE-407
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to inefficient algorithmic complexity in QUIC stream fragment reassembly when handling out-of-order stream fragments. A remote user can manipulate stream fragment offsets to cause a denial of service.

Exploitation requires completion of the QUIC handshake and can use compliant STREAM frames within the advertised receive window.


Affected software

OpenSSL
Debian Linux
openssl (Debian package)

How to mitigate CVE-2026-42772

Install security update from vendor's website.

OpenSSL - addressed in versions 1.0.2zs, 1.1.1zj, 3.0.23, 3.4.8, 3.5.9, 3.6.5, 4.0.3
openssl (Debian package) - update to 3.5.7-1~deb13u3

External References

Related Security Bulletins