CVE-2026-42772: Potential CPU DoS via O(n^2) Fragment Reassembly in QUIC
Issue summary: The QUIC stream reassembly algorithm performance deteriorates progressively as packets are arriving out of order. The worst case has a quadratic complexity proportional to the number of stream frames kept in the buffer for the received stream data.
Impact summary: A remote QUIC peer that completes the handshake can create a connection-scoped CPU pressure and potentially a Denial of Service using compliant STREAM frames inside the advertised receive window, with low attacker bandwidth.
CWE: CWE-407: Inefficient Algorithmic Complexity
Description: OpenSSL manages received QUIC stream fragments using a doubly-linked list. While it optimizes for append operations (at the end of the list), it falls back to a head-to-tail linear search for any fragment that does not immediately follow the current tail.
By manipulating the sequence of offsets, an attacker can force the server to perform O(n^2) operations, consuming excessive CPU time for the QUIC process.
FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to do to trigger the CPU pressure?
The attacker must act as a remote QUIC peer and complete the QUIC handshake. They can then send compliant STREAM frames with manipulated out-of-order offsets within the advertised receive window; malformed frames are not required.
Is the OpenSSL FIPS module affected?
No. The QUIC implementation is outside the OpenSSL FIPS module boundary, so the FIPS module is not affected.