<Vulnerability name="CVE-2026-34183">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Moderate</ThreatSeverity>
    <PublicDate>2026-06-09T00:00:00</PublicDate>
    <Bugzilla id="2481885" url="https://bugzilla.redhat.com/show_bug.cgi?id=2481885" xml:lang="en:us">
openssl: Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler
    </Bugzilla>
    <CVSS3 status="verified">
        <CVSS3BaseScore>7.5</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-770</CWE>
    <Details xml:lang="en:us" source="Mitre">
Issue summary: Remote peer may exhaust heap memory of the QUIC
server or client by flooding it with packets containing PATH_CHALLENGE
frames.

Impact summary: A malicious remote peer can cause an unbounded
memory allocation which can lead to an abnormal termination of the
application acting as a QUIC client or server and a Denial of Service.

A remote peer may exhaust heap memory by flooding the local
QUIC stack with PATH_CHALLENGE frames. The local QUIC stack
allocates a PATH_RESPONSE frame for every PATH_CHALLENGE it receives.
The allocated PATH_RESPONSE frame gets freed only when the remote
peer acknowledges reception of the PATH_RESPONSE frame which will
not be done by a malicious peer.

The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by
this issue. The QUIC stack is outside of OpenSSL FIPS module
boundary.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in OpenSSL's QUIC PATH_CHALLENGE handler. A remote attacker can exploit this vulnerability by flooding a QUIC client or server with specially crafted PATH_CHALLENGE frames. This leads to unbounded memory allocation within the local QUIC stack, as the system continuously allocates PATH_RESPONSE frames without them being acknowledged. The primary consequence is a Denial of Service (DoS), causing the affected application to terminate abnormally due to memory exhaustion.
    </Details>
    <Statement xml:lang="en:us">
A Moderate severity flaw exists in the QUIC PATH_CHALLENGE handler, allowing a remote attacker to exhaust heap memory of a QUIC client or server. By flooding the local QUIC stack with PATH_CHALLENGE frames, a malicious peer can trigger unbounded memory allocation, leading to a denial of service for applications utilizing the vulnerable QUIC implementation.
    </Statement>
    <Mitigation xml:lang="en:us">
To mitigate this vulnerability, apply UDP rate limiting at your network edge to throttle malicious traffic. If QUIC is not strictly required, disable the listener entirely and configure your application to use standard TLS over TCP. Additionally, enforce strict process memory limits using cgroups to prevent host-wide memory exhaustion during an attack.
    </Mitigation>
    <AffectedRelease cpe="cpe:/o:redhat:enterprise_linux:10.2">
        <ProductName>Red Hat Enterprise Linux 10</ProductName>
        <ReleaseDate>2026-06-11T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:25237">RHSA-2026:25237</Advisory>
        <Package name="openssl">openssl-1:3.5.5-4.el10_2</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:enterprise_linux:9">
        <ProductName>Red Hat Enterprise Linux 9</ProductName>
        <ReleaseDate>2026-06-11T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:25239">RHSA-2026:25239</Advisory>
        <Package name="openssl">openssl-1:3.5.5-4.el9_8</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/o:redhat:enterprise_linux:9">
        <ProductName>Red Hat Enterprise Linux 9</ProductName>
        <ReleaseDate>2026-06-11T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:25239">RHSA-2026:25239</Advisory>
        <Package name="openssl">openssl-1:3.5.5-4.el9_8</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:cost_management:4::el9">
        <ProductName>Cost Management 4</ProductName>
        <ReleaseDate>2026-07-15T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:39981">RHSA-2026:39981</Advisory>
        <Package name="costmanagement/costmanagement-metrics-rhel9-operator">costmanagement/costmanagement-metrics-rhel9-operator:1783539156</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:discovery:2::el9">
        <ProductName>Red Hat Discovery 2</ProductName>
        <ReleaseDate>2026-06-24T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:29197">RHSA-2026:29197</Advisory>
        <Package name="discovery/discovery-server-rhel9">discovery/discovery-server-rhel9:1782159791</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:discovery:2::el9">
        <ProductName>Red Hat Discovery 2</ProductName>
        <ReleaseDate>2026-06-24T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:29197">RHSA-2026:29197</Advisory>
        <Package name="discovery/discovery-ui-rhel9">discovery/discovery-ui-rhel9:1782166952</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:insights_proxy:1.5::el9">
        <ProductName>Red Hat Insights proxy 1.5</ProductName>
        <ReleaseDate>2026-07-01T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:34102">RHSA-2026:34102</Advisory>
        <Package name="insights-proxy/insights-proxy-container-rhel9">insights-proxy/insights-proxy-container-rhel9:1782890503</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:rhui:5::el9">
        <ProductName>Red Hat Update Infrastructure 5</ProductName>
        <ReleaseDate>2026-06-16T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:26319">RHSA-2026:26319</Advisory>
        <Package name="rhui5/cds-rhel9">rhui5/cds-rhel9:1781525684</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:rhui:5::el9">
        <ProductName>Red Hat Update Infrastructure 5</ProductName>
        <ReleaseDate>2026-06-16T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:26319">RHSA-2026:26319</Advisory>
        <Package name="rhui5/haproxy-rhel9">rhui5/haproxy-rhel9:1781525671</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:rhui:5::el9">
        <ProductName>Red Hat Update Infrastructure 5</ProductName>
        <ReleaseDate>2026-06-16T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:26319">RHSA-2026:26319</Advisory>
        <Package name="rhui5/installer-rhel9">rhui5/installer-rhel9:1781525693</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:rhui:5::el9">
        <ProductName>Red Hat Update Infrastructure 5</ProductName>
        <ReleaseDate>2026-06-16T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:26319">RHSA-2026:26319</Advisory>
        <Package name="rhui5/rhua-rhel9">rhui5/rhua-rhel9:1781525739</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:rhui:5::el9">
        <ProductName>Red Hat Update Infrastructure 5</ProductName>
        <ReleaseDate>2026-08-24T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:58981">RHSA-2026:58981</Advisory>
        <Package name="rhui5/cds-kubernetes-tp-rhel9">rhui5/cds-kubernetes-tp-rhel9:1787241211</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:rhui:5::el9">
        <ProductName>Red Hat Update Infrastructure 5</ProductName>
        <ReleaseDate>2026-08-24T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:58981">RHSA-2026:58981</Advisory>
        <Package name="rhui5/installer-tp-rhel9">rhui5/installer-tp-rhel9:1787135742</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:rhui:5::el9">
        <ProductName>Red Hat Update Infrastructure 5</ProductName>
        <ReleaseDate>2026-08-24T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:58981">RHSA-2026:58981</Advisory>
        <Package name="rhui5/rhua-tp-rhel9">rhui5/rhua-tp-rhel9:1787241260</Package>
    </AffectedRelease>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:10">
        <ProductName>Red Hat Enterprise Linux 10</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>edk2</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:10">
        <ProductName>Red Hat Enterprise Linux 10</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>shim</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:10">
        <ProductName>Red Hat Enterprise Linux 10</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>shim-unsigned-aarch64</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:10">
        <ProductName>Red Hat Enterprise Linux 10</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>shim-unsigned-x64</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:6">
        <ProductName>Red Hat Enterprise Linux 6</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>openssl</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:7">
        <ProductName>Red Hat Enterprise Linux 7</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>ovmf</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:8">
        <ProductName>Red Hat Enterprise Linux 8</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>compat-openssl10</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:8">
        <ProductName>Red Hat Enterprise Linux 8</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>edk2</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:8">
        <ProductName>Red Hat Enterprise Linux 8</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>mingw-openssl</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:8">
        <ProductName>Red Hat Enterprise Linux 8</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>openssl</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:8">
        <ProductName>Red Hat Enterprise Linux 8</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>shim</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:8">
        <ProductName>Red Hat Enterprise Linux 8</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>shim-unsigned-x64</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:9">
        <ProductName>Red Hat Enterprise Linux 9</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>compat-openssl11</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:9">
        <ProductName>Red Hat Enterprise Linux 9</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>edk2</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:9">
        <ProductName>Red Hat Enterprise Linux 9</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>shim</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:9">
        <ProductName>Red Hat Enterprise Linux 9</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>shim-unsigned-aarch64</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:9">
        <ProductName>Red Hat Enterprise Linux 9</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>shim-unsigned-x64</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:jboss_core_services:1">
        <ProductName>Red Hat JBoss Core Services</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>jbcs-httpd24-openssl</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:jboss_core_services:1">
        <ProductName>Red Hat JBoss Core Services</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>jbcs-openssl-win6-x86_64.zip</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:jboss_enterprise_web_server:6">
        <ProductName>Red Hat JBoss Web Server 6</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>jws-optional-native-components-win6-x86_64.zip</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:jboss_enterprise_web_server:7">
        <ProductName>Red Hat JBoss Web Server 7</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>jws-optional-native-components-win6-x86_64.zip</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift:4">
        <ProductName>Red Hat OpenShift Container Platform 4</ProductName>
        <FixState>Affected</FixState>
        <PackageName>openshift/ose-rhel-coreos-8</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift:4">
        <ProductName>Red Hat OpenShift Container Platform 4</ProductName>
        <FixState>Affected</FixState>
        <PackageName>openshift/ose-rhel-coreos-9</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-34183
https://nvd.nist.gov/vuln/detail/CVE-2026-34183
    </References>
</Vulnerability>