Junglewise Threat Intelligence

CVE-2026-42764: OpenSSL NULL pointer dereference in QUIC server initial packet handling

CVE-2026-42764 · Severity: info · CVSS 5.3 · Published 2026-06-09

Technologies: OpenSSL Foundation OpenSSL.

Executive brief

OpenSSL is a widely used security library that provides encrypted communications for websites and applications. A vulnerability in its QUIC server implementation allows an attacker to crash the server by sending a specially crafted network packet. This could lead to a service outage, although it only affects servers where specific non-default address validation settings have been disabled.

Technical details

A NULL pointer dereference vulnerability exists in the OpenSSL QUIC server's handling of initial packets. When a server is configured with address validation disabled (specifically using the SSL_LISTENER_FLAG_NO_VALIDATE flag in SSL_new_listener()), receiving a QUIC initial packet with an invalid or expired token triggers the crash. This results in a Denial of Service (DoS) as the server process terminates abnormally. The vulnerability is reachable from the network without authentication, but the default configuration (where address validation is enabled) is not affected. FIPS modules are also unaffected as the QUIC stack resides outside the FIPS boundary.

Affected products

  • OpenSSL Foundation OpenSSL 3.4, 3.5, 3.6, 4.0

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References