CVE-2026-84784: QUIC: Unbounded RETIRE_CONNECTION_ID Backlog
Issue summary: A malicious remote peer may flood the local QUIC stack with NEWCONNECTIONID frames by avoiding a limit check on how many connection IDs the remote QUIC stack can use.
Other sources
QUIC: Unbounded RETIRECONNECTIONID Backlog
— Debian
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/opensslto a version that resolves this vulnerability.Fixed in 3.0.20-1~deb12u2Fixed in 3.0.22-1~deb12u1
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Deployments using the affected OpenSSL QUIC stack that accept connections from malicious remote QUIC peers are exposed. The attack occurs on an existing QUIC connection and does not require the peer to acknowledge the control frames it causes the local stack to queue.
What must an attacker do to drive memory consumption?
The remote peer sends many NEW_CONNECTION_ID frames while avoiding the limit on remote connection IDs. It also withholds ACKs, preventing the locally generated RETIRE_CONNECTION_ID frames from being cleared from the Control Frame Queue.
How large can the resource impact be?
The local stack can be forced to allocate approximately 400 MB, with the amount depending on ACK delay. The queued RETIRE_CONNECTION_ID frames are the source of the allocation growth.