目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-42772— Potential CPU DoS via O(n^2) Fragment Reassembly in QUIC

一分钟漏洞结论

影响对象
OpenSSL OpenSSL
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

Issue summary: The QUIC stream reassembly algorithm performance deteriorates progressively as packets are arriving out of order. The worst case has a quadratic complexity proportional to the number of stream frames kept in the buffer for the received stream da

获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-42772 基础信息

漏洞信息

Shenlong is analyzing...


对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Potential CPU DoS via O(n^2) Fragment Reassembly in QUIC
来源: CVE Program / CVE List V5
Vulnerability Description
Issue summary: The QUIC stream reassembly algorithm performance deteriorates progressively as packets are arriving out of order. The worst case has a quadratic complexity proportional to the number of stream frames kept in the buffer for the received stream data. Impact summary: A remote QUIC peer that completes the handshake can create a connection-scoped CPU pressure and potentially a Denial of Service using compliant STREAM frames inside the advertised receive window, with low attacker bandwidth. CWE: CWE-407: Inefficient Algorithmic Complexity Description: OpenSSL manages received QUIC stream fragments using a doubly-linked list. While it optimizes for append operations (at the end of the list), it falls back to a head-to-tail linear search for any fragment that does not immediately follow the current `tail`. By manipulating the sequence of offsets, an attacker can force the server to perform O(n^2) operations, consuming excessive CPU time for the QUIC process. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary.
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
算法复杂性
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
OpenSSL OpenSSL 4.0.0 ~ 4.0.3 -

二、漏洞 CVE-2026-42772 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-42772 的情报信息

请登录查看更多情报信息。

CVE-2026-42772 其他参考 (5)

同批安全公告 · OpenSSL · 2026-09-29 · 共 14 条

CVE-2026-35189 Excessive Memory Allocation in Relative CRLDP Processing
CVE-2026-35191 QUIC Unvalidated Amplification Credit may be Over Accounted
CVE-2026-75806 Unauthenticated and Undersized DTLS 1.2 AEAD Record Causes DoS
CVE-2026-75804 QUIC Connection-Level Flow Control is Not Enforced for Streams
CVE-2026-75805 NULL Pointer Dereference in CMP Client Revocation Response Handling
CVE-2026-54873 QUIC STREAM Fragment Metadata DoS
CVE-2026-54872 Timing Side-Channel in Scalar Multiplication for Non-NIST EC Curves
CVE-2026-54875 Non-Constant-Time SM2 Scalar Multiplication on ARM64 and RISC-V
CVE-2026-77696 Timing Side-Channel in SM2 Signature Generation
CVE-2026-72897 Out-of-Bounds Access After SSL_set_SSL_CTX() During a Handshake
CVE-2026-84782 DTLS Retransmits Handshake Messages From a Stale Buffer Offset
CVE-2026-84784 QUIC: Unbounded RETIRE_CONNECTION_ID Backlog
CVE-2026-84783 Use-After-Free in X.509 Extension Cache Under Concurrent Use

IV. Related Vulnerabilities

V. Comments for CVE-2026-42772

暂无评论


发表评论