← All Advisories

CVE-2026-18798

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-18798

Key Details

CVECVE-2026-18798
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-09-23
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is none; availability impact is high.
Affected productsopenssl openssl
Classified asCWE-415 (Double Free)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
opensslopenssl
SubsystemsGeneral OT
SectorsMultiple

What to Know

Issue summary: QUIC server may double free QRX (QUIC record layer RX) object

when channel creation fails for initial packet.

Impact summary: Double free leads to heap corruption, which typically results in

termination of QUIC server process, leading to Denial of Service. There is so

far no evidence that this double free is exploitable for remote code execution,

thus it is considered highly improbable.

CWE: CWE-415: Double Free

Description: In order to validate initial packet, OpenSSL QUIC stack default

packet handler (port_default_packet_handler()) creates a so-called QRX object.

If the initial packet validates successfully with QRX object, the default packet

handler proceeds to channel (connection object) creation. The QRX object used

for packet validation is passed to port_bind_channel(), so it becomes part of

the newly created connection. If port_bind_channel() fails, then it also frees

the QRX object. Once port_bind_channel() returns, the port_default_packet_handler()

detects the failure and proceeds to the error branch, where the same QRX object is

freed for the second time.

The failure in port_bind_channel() function can be induced with a relatively

low effort by a malformed (non RFC 9000 compliant) INITIAL packet. If the packet

carries DCID (destination connection ID) which is shorter than 8 bytes, then

port_bind_channel() jumps to the error path after ossl_quic_lcidm_enrol_odcid()

detects that the DCID has invalid length.

FIPS impact: no

The FIPS module is not affected, as the QUIC implementation is outside of

the OpenSSL FIPS module boundary. (NVD)

What to Do

Monitor openssl's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-18798
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-18798
Vendor advisoryhttps://openssl-library.org/news/secadv/20260825.txt