CVE-2026-35191: QUIC Unvalidated Amplification Credit may be Over Accounted
Issue summary: The OpenSSL QUIC server, when configured to not preform address validation, can be forced to count incoming packets multiple times in its unvalidated credit computation, leading to a violation of the RFC 9000 unvalidated connection amplification limit of 3 times the amount of data received.
Other sources
QUIC Unvalidated Amplification Credit may be Over Accounted
— Debian
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 3.0.20-1~deb12u2Fixed in 3.0.22-1~deb12u1
Event History
Frequently Asked Questions
Which deployments are exposed?
OpenSSL deployments using the QUIC stack as a server are affected only when client address validation has been disabled. The issue concerns the pre-handshake limit on traffic sent to an unvalidated peer address.
What does an attacker need to exploit this?
An attacker must be able to send spoofed packets to the affected QUIC server. The flaw can allow the server to send more than the RFC 9000 three-to-one amplification limit, making it usable in a DDoS amplification attack.
What can be done if updates cannot be applied immediately?
Enable client address validation on the QUIC server rather than operating in non-validation mode. The described accounting error occurs specifically when address validation is disabled.