Executive brief
OpenSSL's QUIC (Quick UDP Internet Connections) implementation contains a double-free memory vulnerability in its packet handling logic. When a malformed network packet triggers channel creation to fail, the same memory object is freed twice, corrupting the heap and crashing the QUIC server process. This results in service unavailability for applications relying on OpenSSL's QUIC protocol support.
Technical details
The vulnerability is a double-free (CWE-415) in the port_default_packet_handler() function within OpenSSL's QUIC stack. When validating an initial QUIC packet, a QRX (QUIC record layer RX) object is created for validation. If validation succeeds but subsequent channel creation via port_bind_channel() fails—triggered by a malformed INITIAL packet with an invalid-length DCID (destination connection ID shorter than 8 bytes)—the QRX object is freed twice: once by port_bind_channel() on error and again by the default handler's error branch. Exploitation requires network-level access to send a non-RFC 9000 compliant QUIC INITIAL packet. The result is heap corruption and process termination (denial of service); remote code execution is considered highly improbable.
Affected products
- OpenSSL OpenSSL <UNKNOWN>
Timeline
- 2026-08-25: disclosed