{"id":"CVE-2026-84784","summary":"QUIC: Unbounded RETIRE_CONNECTION_ID Backlog","details":"Issue summary: A malicious remote peer may flood the local QUIC\nstack with NEW_CONNECTION_ID frames by avoiding a limit check on\nhow many connection IDs the remote QUIC stack can use.\n\nImpact summary: The local QUIC stack sends a RETIRE_CONN_ID frame\nfor every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID\nframe is dispatched via the Control Frame Queue (CFQ). If the remote\npeer also withholds ACKs, then it can force the local stack\nto allocate ~400MB (depending on ACK delay).\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism\nby which a remote peer can notify the local QUIC stack to change the\ndestination connection ID (a.k.a. CID) the local stack uses to\nidentify the connection at the remote peer. Each CID is associated\nwith a sequence number. The sequence number is transmitted\nin NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID\nwhich is being either associated with a connection or retired.\n\nThe remote peer sends a NEW_CONNECTION_ID frame to let the local stack know\na new CID is being associated with an existing connection. The\nNEW_CONNECTION_ID frame carries the new CID, its sequence number, and the\nretire-prior-to number. The retire-prior-to identifies existing\nCIDs that are to be retired. The local QUIC stack must send a\nRETIRE_CONNECTION_ID for every destination CID whose sequence number\nis less than retire-prior-to. The CID becomes retired after the\nlocal stack receives an ACK for its RETIRE_CONNECTION_ID frame.\n\nAlthough the OpenSSL QUIC stack supports at most one destination CID\nfor every connection, it can be tricked into processing more than\none RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC\nstack currently retires the destination CID as soon as it receives\nthe NEW_CONNECTION_ID, while in fact the destination CID must\nbe retired after an ACK for the RETIRE_CONNECTION_ID frame is received.\nCorrecting the flawed logic also fixes the backlog growth.\n\n[1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids\n\nFIPS impact: no\nThe FIPS module is not affected as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary.","modified":"2026-10-01T08:07:31.807388Z","published":"2026-09-29T15:32:25.758Z","database_specific":{"cna_assigner":"openssl","cwe_ids":["CWE-770"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/84xxx/CVE-2026-84784.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/84xxx/CVE-2026-84784.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84784"},{"type":"ADVISORY","url":"https://openssl-library.org/news/secadv/20260929.txt"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/4685c914b0d410b1034f40b547c95bc95e7a380a"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/9a30fe0fba195c14e5b87bf93c0d0fdb70373806"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/dba3c48d653c64fcbc9070a17a0ee2b3e2f3af1f"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/e9e5155833fa968bee50024bf9ca3a185ab599fe"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/openssl/openssl","events":[{"introduced":"11b7b6ea3b65a584e1d31408ed1bdb139465cffd"},{"introduced":"7b371d80d959ec9ab4139d09d78e83c090de9779"},{"introduced":"636dfadc70ce26f2473870570bfd9ec352806b1d"},{"introduced":"98acb6b02839c609ef5b837794e08d906d965335"},{"fixed":"af1775b60dfa141a4ad762585052cabeb9f37e9e"},{"fixed":"c8bd5a57108599ac650bbae77fcabe3109dab2e8"},{"fixed":"45e844fa2a14ec92d146bd8f5778ac130b6625fb"},{"fixed":"e72c946f6f6d94c8ba5119acb25340b7b6b2073f"},{"fixed":"4685c914b0d410b1034f40b547c95bc95e7a380a"},{"fixed":"9a30fe0fba195c14e5b87bf93c0d0fdb70373806"},{"fixed":"dba3c48d653c64fcbc9070a17a0ee2b3e2f3af1f"},{"fixed":"e9e5155833fa968bee50024bf9ca3a185ab599fe"}],"database_specific":{"extracted_events":[{"introduced":"4.0.0"},{"fixed":"4.0.3"},{"introduced":"3.6.0"},{"fixed":"3.6.5"},{"introduced":"3.5.0"},{"fixed":"3.5.9"},{"introduced":"3.4.0"},{"fixed":"3.4.8"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["openssl-3.4.7","openssl-3.5.8","openssl-3.6.4","openssl-4.0.2","openssl-3.4.6","openssl-3.5.7","openssl-3.6.3","openssl-4.0.1","openssl-4.0.0","openssl-3.4.5","openssl-3.5.6","openssl-3.6.2","openssl-3.4.4","openssl-3.5.5","openssl-3.6.1","3.4-POST-CLANG-FORMAT-WEBKIT","3.4-PRE-CLANG-FORMAT-WEBKIT","3.5-POST-CLANG-FORMAT-WEBKIT","3.5-PRE-CLANG-FORMAT-WEBKIT","3.6-POST-CLANG-FORMAT-WEBKIT","3.6-PRE-CLANG-FORMAT-WEBKIT","openssl-3.6.0","openssl-3.4.3","openssl-3.5.4","openssl-3.5.3","openssl-3.5.2","openssl-3.4.2","openssl-3.5.1","openssl-3.5.0","openssl-3.4.1","openssl-3.4.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-84784.json","vanir_signatures_modified":"2026-10-01T08:07:31Z","vanir_signatures":[{"target":{"file":"ssl/quic/quic_channel.c","function":"ch_enqueue_retire_conn_id"},"deprecated":false,"digest":{"function_hash":"34997640861911039303014508048989038668","length":784},"id":"CVE-2026-84784-088de626","signature_type":"Function","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/4685c914b0d410b1034f40b547c95bc95e7a380a"},{"target":{"file":"ssl/quic/quic_channel.c","function":"free_frame_data"},"deprecated":false,"digest":{"length":103,"function_hash":"44359787970268970062115399894937805486"},"id":"CVE-2026-84784-2102dd8f","signature_type":"Function","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/e9e5155833fa968bee50024bf9ca3a185ab599fe"},{"signature_version":"v1","source":"https://github.com/openssl/openssl/commit/9a30fe0fba195c14e5b87bf93c0d0fdb70373806","target":{"file":"ssl/quic/quic_channel.c"},"deprecated":false,"digest":{"line_hashes":["201660344150385936081037765180087768685","155944247079012445664641611371872850374","37684021460279698712126160981161767432","25713537654284790046282956640724532799","235034100442889237116797621785671585102","324678174358907110497941236448960628028","14284455215888359692301294154199032896","97360435952137816603724222798964367112","20392748306564267683379630388341426787","266161356460588329450249029502186614717","230058973664600946447126508875329623771","1827748206435545166149709930188930306","332830942557596951662314141814254474400","331324964858101394638513795137677459344","302251434773735382636889880742976177005","235220946724171783798103255683095335692","207525007180875373041840614807304979092","9239382761901516317852820233779077661","195278179499011949757859760724496224891","148839100518996897092894363487242737096","262548102060552940356766003227350455540","193759298105244652445539167741252742783","273991221879916277080741807512159544211","177741196636415753465370482689742573162","225032495860952299226604861473017628733","37126588150201971460019310072891686078","15211756495511365696065897855021517868","130703459814230308998533405078278849686","270940732520151275291299411299183142958","232802937324108053937267465922353802382","271563566373451074140339874064196801404","173802038047283645775342328860246305239","25462046066204002758026798783577069721","36086374762634932243945376911706511589","78542178178011556322727689778386723525"],"threshold":0.9},"id":"CVE-2026-84784-3ade5fb8","signature_type":"Line"},{"source":"https://github.com/openssl/openssl/commit/dba3c48d653c64fcbc9070a17a0ee2b3e2f3af1f","target":{"file":"ssl/quic/quic_channel.c","function":"ch_enqueue_retire_conn_id"},"deprecated":false,"digest":{"function_hash":"34997640861911039303014508048989038668","length":784},"id":"CVE-2026-84784-56a3d2a0","signature_type":"Function","signature_version":"v1"},{"target":{"file":"ssl/quic/quic_channel.c","function":"ossl_quic_channel_on_new_conn_id"},"deprecated":false,"digest":{"function_hash":"64074164771038874937186414424441091995","length":1425},"id":"CVE-2026-84784-5a9885bc","signature_type":"Function","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/e9e5155833fa968bee50024bf9ca3a185ab599fe"},{"id":"CVE-2026-84784-5c11edd0","signature_type":"Function","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/4685c914b0d410b1034f40b547c95bc95e7a380a","target":{"file":"ssl/quic/quic_channel.c","function":"free_frame_data"},"deprecated":false,"digest":{"function_hash":"44359787970268970062115399894937805486","length":103}},{"signature_version":"v1","source":"https://github.com/openssl/openssl/commit/4685c914b0d410b1034f40b547c95bc95e7a380a","target":{"file":"ssl/quic/quic_channel.c","function":"ossl_quic_channel_on_new_conn_id"},"deprecated":false,"digest":{"function_hash":"64074164771038874937186414424441091995","length":1425},"id":"CVE-2026-84784-7fd612a1","signature_type":"Function"},{"signature_version":"v1","source":"https://github.com/openssl/openssl/commit/dba3c48d653c64fcbc9070a17a0ee2b3e2f3af1f","target":{"file":"ssl/quic/quic_channel.c","function":"ossl_quic_channel_on_new_conn_id"},"deprecated":false,"digest":{"function_hash":"64074164771038874937186414424441091995","length":1425},"id":"CVE-2026-84784-85dc84f5","signature_type":"Function"},{"source":"https://github.com/openssl/openssl/commit/e9e5155833fa968bee50024bf9ca3a185ab599fe","target":{"file":"ssl/quic/quic_channel.c"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["217847804862288742574802933739910620651","155944247079012445664641611371872850374","37684021460279698712126160981161767432","25713537654284790046282956640724532799","235034100442889237116797621785671585102","324678174358907110497941236448960628028","14284455215888359692301294154199032896","97360435952137816603724222798964367112","20392748306564267683379630388341426787","266161356460588329450249029502186614717","230058973664600946447126508875329623771","1827748206435545166149709930188930306","332830942557596951662314141814254474400","331324964858101394638513795137677459344","302251434773735382636889880742976177005","235220946724171783798103255683095335692","207525007180875373041840614807304979092","9239382761901516317852820233779077661","195278179499011949757859760724496224891","148839100518996897092894363487242737096","262548102060552940356766003227350455540","193759298105244652445539167741252742783","273991221879916277080741807512159544211","177741196636415753465370482689742573162","225032495860952299226604861473017628733","37126588150201971460019310072891686078","15211756495511365696065897855021517868","130703459814230308998533405078278849686","270940732520151275291299411299183142958","232802937324108053937267465922353802382","271563566373451074140339874064196801404","173802038047283645775342328860246305239","25462046066204002758026798783577069721","36086374762634932243945376911706511589","78542178178011556322727689778386723525"]},"id":"CVE-2026-84784-9bba8144","signature_type":"Line","signature_version":"v1"},{"digest":{"line_hashes":["217847804862288742574802933739910620651","155944247079012445664641611371872850374","37684021460279698712126160981161767432","25713537654284790046282956640724532799","235034100442889237116797621785671585102","324678174358907110497941236448960628028","14284455215888359692301294154199032896","97360435952137816603724222798964367112","20392748306564267683379630388341426787","266161356460588329450249029502186614717","230058973664600946447126508875329623771","1827748206435545166149709930188930306","332830942557596951662314141814254474400","331324964858101394638513795137677459344","302251434773735382636889880742976177005","235220946724171783798103255683095335692","207525007180875373041840614807304979092","9239382761901516317852820233779077661","195278179499011949757859760724496224891","148839100518996897092894363487242737096","262548102060552940356766003227350455540","193759298105244652445539167741252742783","273991221879916277080741807512159544211","177741196636415753465370482689742573162","225032495860952299226604861473017628733","37126588150201971460019310072891686078","15211756495511365696065897855021517868","130703459814230308998533405078278849686","270940732520151275291299411299183142958","232802937324108053937267465922353802382","271563566373451074140339874064196801404","173802038047283645775342328860246305239","25462046066204002758026798783577069721","36086374762634932243945376911706511589","78542178178011556322727689778386723525"],"threshold":0.9},"id":"CVE-2026-84784-a2774ad3","signature_type":"Line","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/dba3c48d653c64fcbc9070a17a0ee2b3e2f3af1f","target":{"file":"ssl/quic/quic_channel.c"},"deprecated":false},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/9a30fe0fba195c14e5b87bf93c0d0fdb70373806","target":{"file":"ssl/quic/quic_channel.c","function":"ossl_quic_channel_on_new_conn_id"},"deprecated":false,"digest":{"function_hash":"64074164771038874937186414424441091995","length":1425},"id":"CVE-2026-84784-bcc23140"},{"id":"CVE-2026-84784-bce71c1b","signature_type":"Function","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/dba3c48d653c64fcbc9070a17a0ee2b3e2f3af1f","target":{"file":"ssl/quic/quic_channel.c","function":"free_frame_data"},"deprecated":false,"digest":{"function_hash":"44359787970268970062115399894937805486","length":103}},{"signature_version":"v1","source":"https://github.com/openssl/openssl/commit/4685c914b0d410b1034f40b547c95bc95e7a380a","target":{"file":"ssl/quic/quic_channel.c"},"deprecated":false,"digest":{"line_hashes":["217847804862288742574802933739910620651","155944247079012445664641611371872850374","37684021460279698712126160981161767432","25713537654284790046282956640724532799","235034100442889237116797621785671585102","324678174358907110497941236448960628028","14284455215888359692301294154199032896","97360435952137816603724222798964367112","20392748306564267683379630388341426787","266161356460588329450249029502186614717","230058973664600946447126508875329623771","1827748206435545166149709930188930306","332830942557596951662314141814254474400","331324964858101394638513795137677459344","302251434773735382636889880742976177005","235220946724171783798103255683095335692","207525007180875373041840614807304979092","9239382761901516317852820233779077661","195278179499011949757859760724496224891","148839100518996897092894363487242737096","262548102060552940356766003227350455540","193759298105244652445539167741252742783","273991221879916277080741807512159544211","177741196636415753465370482689742573162","225032495860952299226604861473017628733","37126588150201971460019310072891686078","15211756495511365696065897855021517868","130703459814230308998533405078278849686","270940732520151275291299411299183142958","232802937324108053937267465922353802382","271563566373451074140339874064196801404","173802038047283645775342328860246305239","25462046066204002758026798783577069721","36086374762634932243945376911706511589","78542178178011556322727689778386723525"],"threshold":0.9},"id":"CVE-2026-84784-c33cf31b","signature_type":"Line"},{"digest":{"function_hash":"44359787970268970062115399894937805486","length":103},"id":"CVE-2026-84784-cb97e81d","signature_type":"Function","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/9a30fe0fba195c14e5b87bf93c0d0fdb70373806","target":{"file":"ssl/quic/quic_channel.c","function":"free_frame_data"},"deprecated":false},{"source":"https://github.com/openssl/openssl/commit/9a30fe0fba195c14e5b87bf93c0d0fdb70373806","target":{"function":"ch_enqueue_retire_conn_id","file":"ssl/quic/quic_channel.c"},"deprecated":false,"digest":{"function_hash":"34997640861911039303014508048989038668","length":784},"id":"CVE-2026-84784-eaf68cf4","signature_type":"Function","signature_version":"v1"},{"deprecated":false,"digest":{"function_hash":"34997640861911039303014508048989038668","length":784},"id":"CVE-2026-84784-fd76423c","signature_type":"Function","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/e9e5155833fa968bee50024bf9ca3a185ab599fe","target":{"file":"ssl/quic/quic_channel.c","function":"ch_enqueue_retire_conn_id"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}