A security notice published on October 1, 2026 reports two vulnerabilities in OpenSSL QUIC streams that may cause denial of service through excessive CPU or memory consumption.
Notice USN-8861-1, published on October 1, 2026 in the Ubuntu Security feed, describes two flaws in OpenSSL processing of QUIC streams. The supplied text is an automatic translation; to confirm the details, consult the original notice through Ubuntu’s official security channel and compare the CVE identifiers.
According to the notice, inefficient reassembly of QUIC streams can increase CPU use (CVE-2026-42772), while insufficient limits on memory allocated to QUIC packet buffers can increase memory use (CVE-2026-54873). In both cases, a remote attacker could cause denial of service. Check the original notice for information applicable to the versions and packages in your environment.