{"id":"AZL-89925","summary":"CVE-2026-34183 affecting package openssl for versions less than 3.3.7-3","details":"Issue summary: Remote peer may exhaust heap memory of the QUIC\nserver or client by flooding it with packets containing PATH_CHALLENGE\nframes.\n\nImpact summary: A malicious remote peer can cause an unbounded\nmemory allocation which can lead to an abnormal termination of the\napplication acting as a QUIC client or server and a Denial of Service.\n\nA remote peer may exhaust heap memory by flooding the local\nQUIC stack with PATH_CHALLENGE frames. The local QUIC stack\nallocates a PATH_RESPONSE frame for every PATH_CHALLENGE it receives.\nThe allocated PATH_RESPONSE frame gets freed only when the remote\npeer acknowledges reception of the PATH_RESPONSE frame which will\nnot be done by a malicious peer.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by\nthis issue. The QUIC stack is outside of OpenSSL FIPS module\nboundary.","modified":"2026-08-30T05:26:50Z","published":"2026-06-09T17:17:05Z","upstream":["CVE-2026-34183"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34183"}],"affected":[{"package":{"name":"openssl","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/openssl"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.3.7-3"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-89925.json"}}],"schema_version":"1.9.0"}