Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with packets containing PATHCHALLENGE frames. Impact summary: A malicious remote peer can cause an unbounded memory allocation which can lead to an abnormal termination of the application acting as a QUIC client or server and a Denial of Service. A remote peer may exhaust heap memory by flooding the local QUIC stack with PATHCHALLENGE frames. The local QUIC stack allocates a PATHRESPONSE frame for every PATHCHALLENGE it receives. The allocated PATHRESPONSE frame gets freed only when the remote peer acknowledges reception of the PATHRESPONSE frame which will not be done by a malicious peer. The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue. The QUIC stack is outside of OpenSSL FIPS module boundary.
{
"binaries": [
{
"binary_name": "efi-shell-aa64",
"binary_version": "2025.02-8ubuntu3.1"
},
{
"binary_name": "efi-shell-arm",
"binary_version": "2025.02-8ubuntu3.1"
},
{
"binary_version": "2025.02-8ubuntu3.1",
"binary_name": "efi-shell-ia32"
},
{
"binary_version": "2025.02-8ubuntu3.1",
"binary_name": "efi-shell-loongarch64"
},
{
"binary_name": "efi-shell-riscv64",
"binary_version": "2025.02-8ubuntu3.1"
},
{
"binary_name": "efi-shell-x64",
"binary_version": "2025.02-8ubuntu3.1"
},
{
"binary_name": "ovmf",
"binary_version": "2025.02-8ubuntu3.1"
},
{
"binary_version": "2025.02-8ubuntu3.1",
"binary_name": "ovmf-ia32"
},
{
"binary_version": "2025.02-8ubuntu3.1",
"binary_name": "ovmf-inteltdx"
},
{
"binary_name": "ovmf-legacy",
"binary_version": "2025.02-8ubuntu3.1"
},
{
"binary_name": "qemu-efi-aarch64",
"binary_version": "2025.02-8ubuntu3.1"
},
{
"binary_name": "qemu-efi-arm",
"binary_version": "2025.02-8ubuntu3.1"
},
{
"binary_name": "qemu-efi-loongarch64",
"binary_version": "2025.02-8ubuntu3.1"
},
{
"binary_version": "2025.02-8ubuntu3.1",
"binary_name": "qemu-efi-riscv64"
}
]
}
{
"availability": "No subscription required",
"binaries": [
{
"binary_version": "3.5.3-1ubuntu3.4",
"binary_name": "libssl3t64"
},
{
"binary_name": "openssl",
"binary_version": "3.5.3-1ubuntu3.4"
},
{
"binary_name": "openssl-provider-legacy",
"binary_version": "3.5.3-1ubuntu3.4"
}
]
}
{
"binaries": [
{
"binary_name": "efi-shell-aa64",
"binary_version": "2025.11-3ubuntu7"
},
{
"binary_name": "efi-shell-loongarch64",
"binary_version": "2025.11-3ubuntu7"
},
{
"binary_name": "efi-shell-riscv64",
"binary_version": "2025.11-3ubuntu7"
},
{
"binary_name": "efi-shell-x64",
"binary_version": "2025.11-3ubuntu7"
},
{
"binary_name": "ovmf",
"binary_version": "2025.11-3ubuntu7"
},
{
"binary_name": "ovmf-amdsev",
"binary_version": "2025.11-3ubuntu7"
},
{
"binary_name": "ovmf-generic",
"binary_version": "2025.11-3ubuntu7"
},
{
"binary_name": "ovmf-inteltdx",
"binary_version": "2025.11-3ubuntu7"
},
{
"binary_name": "ovmf-legacy",
"binary_version": "2025.11-3ubuntu7"
},
{
"binary_name": "qemu-efi-aarch64",
"binary_version": "2025.11-3ubuntu7"
},
{
"binary_name": "qemu-efi-loongarch64",
"binary_version": "2025.11-3ubuntu7"
},
{
"binary_name": "qemu-efi-riscv64",
"binary_version": "2025.11-3ubuntu7"
}
]
}
{
"availability": "No subscription required",
"binaries": [
{
"binary_version": "3.5.5-1ubuntu3.2",
"binary_name": "libssl3t64"
},
{
"binary_version": "3.5.5-1ubuntu3.2",
"binary_name": "openssl"
},
{
"binary_name": "openssl-provider-legacy",
"binary_version": "3.5.5-1ubuntu3.2"
}
]
}