目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-75804— QUIC Connection-Level Flow Control is Not Enforced for Streams

一分钟漏洞结论

影响对象
OpenSSL OpenSSL
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

Issue summary: OpenSSL QUIC stack does not enforce connection level flow control for streams. Remote peers may send more bytes as long as they fit within the stream flow control limits. Impact summary: A malicious remote peer may exploit the lack of connection

获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-75804 基础信息

漏洞信息

Shenlong is analyzing...


对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
QUIC Connection-Level Flow Control is Not Enforced for Streams
来源: CVE Program / CVE List V5
Vulnerability Description
Issue summary: OpenSSL QUIC stack does not enforce connection level flow control for streams. Remote peers may send more bytes as long as they fit within the stream flow control limits. Impact summary: A malicious remote peer may exploit the lack of connection flow control for streams to make the QUIC stack receive ~100MB of memory instead of 768 KiB (default flow control window size). CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: The local QUIC stack advertises two flow control limits to its remote peer: stream flow control limit and connection flow control limit. The remote peer must follow both limits when transmitting stream data. Whenever the local QUIC stack receives a stream frame, it validates that the size of the received stream frame stays within flow control limits. If either limit is exceeded (stream level or connection level), then the QUIC stack must close the connection with a flow control error. The vulnerable OpenSSL QUIC stack enforces the stream-level but not the connection-level limit. To exploit the issue, three conditions must be met: - the remote peer opens several streams - each stream must stay within the stream-level flow control limit - there must be no zero-offset byte sent on any of the streams (to prevent the vulnerable QUIC stack from consuming data). By meeting the conditions above, the remote peer may make the local stack allocate 2 x MAX_STREAMS x (stream flow control limit) bytes of memory. MAX_STREAMS defaults to 100, and the limit applies to both bidirectional and unidirectional streams, making it 200 in total. The default flow control window for a stream is 512kB. The remote peer may force the vulnerable QUIC stack to allocate 100MB of heap per connection. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary.
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
不加限制或调节的资源分配
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
OpenSSL OpenSSL 4.0.0 ~ 4.0.3 -

二、漏洞 CVE-2026-75804 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-75804 的情报信息

请登录查看更多情报信息。

CVE-2026-75804 其他参考 (5)

同批安全公告 · OpenSSL · 2026-09-29 · 共 14 条

CVE-2026-35189 Excessive Memory Allocation in Relative CRLDP Processing
CVE-2026-35191 QUIC Unvalidated Amplification Credit may be Over Accounted
CVE-2026-75806 Unauthenticated and Undersized DTLS 1.2 AEAD Record Causes DoS
CVE-2026-75805 NULL Pointer Dereference in CMP Client Revocation Response Handling
CVE-2026-42772 Potential CPU DoS via O(n^2) Fragment Reassembly in QUIC
CVE-2026-54873 QUIC STREAM Fragment Metadata DoS
CVE-2026-54872 Timing Side-Channel in Scalar Multiplication for Non-NIST EC Curves
CVE-2026-54875 Non-Constant-Time SM2 Scalar Multiplication on ARM64 and RISC-V
CVE-2026-77696 Timing Side-Channel in SM2 Signature Generation
CVE-2026-72897 Out-of-Bounds Access After SSL_set_SSL_CTX() During a Handshake
CVE-2026-84782 DTLS Retransmits Handshake Messages From a Stale Buffer Offset
CVE-2026-84784 QUIC: Unbounded RETIRE_CONNECTION_ID Backlog
CVE-2026-84783 Use-After-Free in X.509 Extension Cache Under Concurrent Use

IV. Related Vulnerabilities

V. Comments for CVE-2026-75804

暂无评论


发表评论