{"id":"USN-8861-1","summary":"openssl vulnerabilities","details":"It was discovered that OpenSSL had an inefficient algorithm in its QUIC\nstream reassembly implementation. A remote attacker could possibly use this\nissue to cause OpenSSL to use excessive CPU resources, leading to a denial\nof service. (CVE-2026-42772)\n\nIt was discovered that OpenSSL did not properly limit memory allocated for\nQUIC packet buffers. A remote attacker could possibly use this issue to\ncause OpenSSL to use excessive memory resources, leading to a denial of\nservice. (CVE-2026-54873)","modified":"2026-10-02T00:42:48.947948485Z","published":"2026-10-01T12:02:00Z","related":["UBUNTU-CVE-2026-42772","UBUNTU-CVE-2026-54873"],"upstream":["CVE-2026-42772","CVE-2026-54873","UBUNTU-CVE-2026-42772","UBUNTU-CVE-2026-54873"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8861-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-42772"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-54873"}],"affected":[{"package":{"name":"openssl","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/openssl?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.5.5-1ubuntu3.7"}]}],"versions":["3.5.3-1ubuntu2","3.5.5-1ubuntu1","3.5.5-1ubuntu3","3.5.5-1ubuntu3.2","3.5.5-1ubuntu3.3","3.5.5-1ubuntu3.4","3.5.5-1ubuntu3.5","3.5.5-1ubuntu3.6"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"libssl3t64","binary_version":"3.5.5-1ubuntu3.7"},{"binary_version":"3.5.5-1ubuntu3.7","binary_name":"openssl"},{"binary_version":"3.5.5-1ubuntu3.7","binary_name":"openssl-provider-legacy"}]},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:26.04:LTS","cves":[{"id":"CVE-2026-42772","severity":[{"type":"Ubuntu","score":"low"}]},{"severity":[{"type":"Ubuntu","score":"low"}],"id":"CVE-2026-54873"}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8861-1.json"}}],"schema_version":"1.9.0"}