CVE-2026-84784: QUIC: Unbounded RETIRE_CONNECTION_ID Backlog

Published Sep 29, 2026
·
Updated

Issue summary: A malicious remote peer may flood the local QUIC stack with NEWCONNECTIONID frames by avoiding a limit check on how many connection IDs the remote QUIC stack can use.

Other sources

QUIC: Unbounded RETIRECONNECTIONID Backlog

— Debian

Affected Software

2 affected componentsFixes available
OpenSSL OpenSSL
debian/openssl<=3.5.7-1~deb13u2, <=3.6.4-1
3.0.20-1~deb12u23.0.22-1~deb12u1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade debian/openssl to a version that resolves this vulnerability.

    Fixed in 3.0.20-1~deb12u2Fixed in 3.0.22-1~deb12u1

Event History

Sep 29, 2026
CVE Published
via MITRE·03:32 PM
Data Sourced
via MITRE·03:32 PM
DescriptionWeakness
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeakness
Data Sourced
via Ubuntu·07:45 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·07:46 PM
Description
Data Sourced
via Debian·07:46 PM
DescriptionAffected Software

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Deployments using the affected OpenSSL QUIC stack that accept connections from malicious remote QUIC peers are exposed. The attack occurs on an existing QUIC connection and does not require the peer to acknowledge the control frames it causes the local stack to queue.

2

What must an attacker do to drive memory consumption?

The remote peer sends many NEW_CONNECTION_ID frames while avoiding the limit on remote connection IDs. It also withholds ACKs, preventing the locally generated RETIRE_CONNECTION_ID frames from being cleared from the Control Frame Queue.

3

How large can the resource impact be?

The local stack can be forced to allocate approximately 400 MB, with the amount depending on ACK delay. The queued RETIRE_CONNECTION_ID frames are the source of the allocation growth.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203