{"id":"CVE-2026-63075","summary":"QUIC ACK-only Packet Retention Can Cause Memory Exhaustion","details":"Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly\nsends ack-eliciting packets while not acknowledging ACK-only responses, the\nQUIC stack can retain ACK-only packet metadata for the lifetime of the\nconnection.\n\nImpact summary: A remote peer that can complete a QUIC handshake can\ncause connection-scoped memory growth which may lead to Denial of Service\nthrough memory exhaustion, especially with sustained traffic or many concurrent\nQUIC connections.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: When the OpenSSL QUIC stack sends an ACK-only packet,\nthere is no requirement by the QUIC protocol that the peer will acknowledge\nthat ACK-only packet (i.e. it is itself not ack-eliciting). However, the OpenSSL\nimplementation stores the metadata about the ACK frames regardless.\nIn and of itself that's ok, but if a malicious peer establishes a connection, and\nthen drives the connection such that ACK-only packets are forced from the \nOpenSSL implementation peer (i.e., by sending numerous PING frames),\nand then withholding any subsequent acks for ack-eliciting data, like\nlegitimate data, said malicious peer can force inappropriate memory growth\non the OpenSSL peer, potentially leading to a Denial of Service.\n\nThe fix is to ensure that we account for the transmission of the ACK-only\npacket in the packet histories high and low watermark without actually storing\nthe ACK-only packet metadata itself.\n\nFIPS impact: no\nThe OpenSSL FIPS module is not affected as the QUIC code is\noutside the FIPS module boundary.","modified":"2026-08-30T08:17:27.730733Z","published":"2026-08-25T13:00:04.752Z","related":["openSUSE-SU-2026:11623-1"],"database_specific":{"cwe_ids":["CWE-770"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63075.json","cna_assigner":"openssl"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63075.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63075"},{"type":"ADVISORY","url":"https://openssl-library.org/news/secadv/20260825.txt"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/7308946576b12e64b8be53bcf0a120354b2b42bc"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/7c98d79738549df92868e7dd9be4bbf061eed709"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/bf84721c2548351176e367e6de505792f0118dc6"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/c902e5f16d6a9e130e96d3ca6d8f64d71652e393"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/openssl/openssl","events":[{"introduced":"11b7b6ea3b65a584e1d31408ed1bdb139465cffd"},{"introduced":"7b371d80d959ec9ab4139d09d78e83c090de9779"},{"introduced":"636dfadc70ce26f2473870570bfd9ec352806b1d"},{"introduced":"98acb6b02839c609ef5b837794e08d906d965335"},{"fixed":"f089acdf4bc7ba94a79f4bf6eb7362c3e7d14aa9"},{"fixed":"d3c1b1169b3569ff3069e5b399f47b2b28e03d79"},{"fixed":"f4dc4d58b48d346a8270183f89acf826d459b0ca"},{"fixed":"0c5d912057abf47505b4ad455da49fbab99b76f1"},{"fixed":"7308946576b12e64b8be53bcf0a120354b2b42bc"},{"fixed":"7c98d79738549df92868e7dd9be4bbf061eed709"},{"fixed":"bf84721c2548351176e367e6de505792f0118dc6"},{"fixed":"c902e5f16d6a9e130e96d3ca6d8f64d71652e393"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"4.0.0"},{"fixed":"4.0.2"},{"introduced":"3.6.0"},{"fixed":"3.6.4"},{"introduced":"3.5.0"},{"fixed":"3.5.8"},{"introduced":"3.4.0"},{"fixed":"3.4.7"}]}}],"versions":["openssl-3.4.6","openssl-3.5.7","openssl-3.6.3","openssl-4.0.1","openssl-4.0.0","openssl-3.4.5","openssl-3.5.6","openssl-3.6.2","openssl-3.4.4","openssl-3.5.5","openssl-3.6.1","3.4-POST-CLANG-FORMAT-WEBKIT","3.4-PRE-CLANG-FORMAT-WEBKIT","3.5-POST-CLANG-FORMAT-WEBKIT","3.5-PRE-CLANG-FORMAT-WEBKIT","3.6-POST-CLANG-FORMAT-WEBKIT","3.6-PRE-CLANG-FORMAT-WEBKIT","openssl-3.6.0","openssl-3.4.3","openssl-3.5.4","openssl-3.5.3","openssl-3.5.2","openssl-3.4.2","openssl-3.5.1","openssl-3.5.0","openssl-3.4.1","openssl-3.4.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63075.json","vanir_signatures_modified":"2026-08-30T08:17:27Z","vanir_signatures":[{"target":{"file":"ssl/quic/quic_txp.c"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["127710184027588375730281123550413388352","238778791714889156187923495759454262098","43228413521986251441327542187044196294","157165095343400443831817287366539372303","208025372272675792743080770736216211694","98469575915396588714434502354077940640","321030774570816453328135141838369112950","119348148652855593112668749738808551759","29246340682027729734788744750284149293","165708783685566916073259555845909499086","194278137406181817761257540485452556920","303357429146340544327831805381917788599","335729294147678692579504856436129565902","217456826098717150031667494494832190521","312756047032349463284920395476681698635","140658052204989063335153801270892005020"]},"id":"CVE-2026-63075-0d25529b","signature_type":"Line","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/7c98d79738549df92868e7dd9be4bbf061eed709"},{"deprecated":false,"digest":{"line_hashes":["127710184027588375730281123550413388352","238778791714889156187923495759454262098","43228413521986251441327542187044196294","157165095343400443831817287366539372303","208025372272675792743080770736216211694","98469575915396588714434502354077940640","321030774570816453328135141838369112950","119348148652855593112668749738808551759","29246340682027729734788744750284149293","165708783685566916073259555845909499086","194278137406181817761257540485452556920","303357429146340544327831805381917788599","335729294147678692579504856436129565902","217456826098717150031667494494832190521","312756047032349463284920395476681698635","140658052204989063335153801270892005020"],"threshold":0.9},"id":"CVE-2026-63075-135e1c69","signature_type":"Line","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/c902e5f16d6a9e130e96d3ca6d8f64d71652e393","target":{"file":"ssl/quic/quic_txp.c"}},{"id":"CVE-2026-63075-16ee1744","signature_type":"Line","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/7c98d79738549df92868e7dd9be4bbf061eed709","target":{"file":"ssl/quic/quic_ackm.c"},"deprecated":false,"digest":{"line_hashes":["93235371864493199705931916959879974733","40152205282306838120683427168311731088","267133881629038346258451224701791507362"],"threshold":0.9}},{"digest":{"line_hashes":["93235371864493199705931916959879974733","40152205282306838120683427168311731088","267133881629038346258451224701791507362"],"threshold":0.9},"id":"CVE-2026-63075-1b91492a","signature_type":"Line","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/c902e5f16d6a9e130e96d3ca6d8f64d71652e393","target":{"file":"ssl/quic/quic_ackm.c"},"deprecated":false},{"deprecated":false,"digest":{"line_hashes":["93235371864493199705931916959879974733","40152205282306838120683427168311731088","267133881629038346258451224701791507362"],"threshold":0.9},"id":"CVE-2026-63075-2b83b044","signature_type":"Line","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/bf84721c2548351176e367e6de505792f0118dc6","target":{"file":"ssl/quic/quic_ackm.c"}},{"target":{"file":"ssl/quic/quic_txp.c","function":"txp_pkt_commit"},"deprecated":false,"digest":{"function_hash":"334889624218050444897162493738252543537","length":3045},"id":"CVE-2026-63075-40ca9834","signature_type":"Function","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/7c98d79738549df92868e7dd9be4bbf061eed709"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/bf84721c2548351176e367e6de505792f0118dc6","target":{"file":"ssl/quic/quic_txp.c","function":"txp_pkt_commit"},"deprecated":false,"digest":{"function_hash":"334889624218050444897162493738252543537","length":3045},"id":"CVE-2026-63075-5bf507d6"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/7308946576b12e64b8be53bcf0a120354b2b42bc","target":{"file":"include/internal/quic_ackm.h"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["223628302570180496787923061552132365924","7216203165409807613722880547111416421","323933867113046269660754449308397129751","72452435522323432164760031484709852745"]},"id":"CVE-2026-63075-7101f9d9"},{"signature_version":"v1","source":"https://github.com/openssl/openssl/commit/7c98d79738549df92868e7dd9be4bbf061eed709","target":{"file":"include/internal/quic_ackm.h"},"deprecated":false,"digest":{"line_hashes":["223628302570180496787923061552132365924","7216203165409807613722880547111416421","323933867113046269660754449308397129751","72452435522323432164760031484709852745"],"threshold":0.9},"id":"CVE-2026-63075-7f23ffeb","signature_type":"Line"},{"deprecated":false,"digest":{"line_hashes":["127710184027588375730281123550413388352","238778791714889156187923495759454262098","43228413521986251441327542187044196294","157165095343400443831817287366539372303","208025372272675792743080770736216211694","98469575915396588714434502354077940640","321030774570816453328135141838369112950","119348148652855593112668749738808551759","29246340682027729734788744750284149293","165708783685566916073259555845909499086","194278137406181817761257540485452556920","303357429146340544327831805381917788599","335729294147678692579504856436129565902","217456826098717150031667494494832190521","312756047032349463284920395476681698635","140658052204989063335153801270892005020"],"threshold":0.9},"id":"CVE-2026-63075-944a2019","signature_type":"Line","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/7308946576b12e64b8be53bcf0a120354b2b42bc","target":{"file":"ssl/quic/quic_txp.c"}},{"id":"CVE-2026-63075-b000da0b","signature_type":"Line","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/bf84721c2548351176e367e6de505792f0118dc6","target":{"file":"ssl/quic/quic_txp.c"},"deprecated":false,"digest":{"line_hashes":["127710184027588375730281123550413388352","238778791714889156187923495759454262098","43228413521986251441327542187044196294","157165095343400443831817287366539372303","208025372272675792743080770736216211694","98469575915396588714434502354077940640","321030774570816453328135141838369112950","119348148652855593112668749738808551759","29246340682027729734788744750284149293","165708783685566916073259555845909499086","194278137406181817761257540485452556920","303357429146340544327831805381917788599","335729294147678692579504856436129565902","217456826098717150031667494494832190521","312756047032349463284920395476681698635","140658052204989063335153801270892005020"],"threshold":0.9}},{"digest":{"line_hashes":["223628302570180496787923061552132365924","7216203165409807613722880547111416421","323933867113046269660754449308397129751","72452435522323432164760031484709852745"],"threshold":0.9},"id":"CVE-2026-63075-df24f473","signature_type":"Line","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/bf84721c2548351176e367e6de505792f0118dc6","target":{"file":"include/internal/quic_ackm.h"},"deprecated":false},{"deprecated":false,"digest":{"line_hashes":["223628302570180496787923061552132365924","7216203165409807613722880547111416421","323933867113046269660754449308397129751","72452435522323432164760031484709852745"],"threshold":0.9},"id":"CVE-2026-63075-e57c3870","signature_type":"Line","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/c902e5f16d6a9e130e96d3ca6d8f64d71652e393","target":{"file":"include/internal/quic_ackm.h"}},{"digest":{"function_hash":"334889624218050444897162493738252543537","length":3045},"id":"CVE-2026-63075-e7b11841","signature_type":"Function","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/7308946576b12e64b8be53bcf0a120354b2b42bc","target":{"file":"ssl/quic/quic_txp.c","function":"txp_pkt_commit"},"deprecated":false},{"source":"https://github.com/openssl/openssl/commit/c902e5f16d6a9e130e96d3ca6d8f64d71652e393","target":{"file":"ssl/quic/quic_txp.c","function":"txp_pkt_commit"},"deprecated":false,"digest":{"function_hash":"334889624218050444897162493738252543537","length":3045},"id":"CVE-2026-63075-e9f34370","signature_type":"Function","signature_version":"v1"},{"signature_version":"v1","source":"https://github.com/openssl/openssl/commit/7308946576b12e64b8be53bcf0a120354b2b42bc","target":{"file":"ssl/quic/quic_ackm.c"},"deprecated":false,"digest":{"line_hashes":["93235371864493199705931916959879974733","40152205282306838120683427168311731088","267133881629038346258451224701791507362"],"threshold":0.9},"id":"CVE-2026-63075-f3aecda8","signature_type":"Line"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}