CVE-2026-42764

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
09/06/2026
Last modified:
23/07/2026

Description

Issue summary: Receiving a QUIC initial packet with an invalid token may<br /> trigger a NULL pointer dereference in the OpenSSL QUIC server with<br /> address validation disabled.<br /> <br /> Impact summary: NULL pointer dereference typically causes abnormal termination<br /> of the affected QUIC server process and a Denial of Service.<br /> <br /> If the address validation is disabled in the OpenSSL QUIC server<br /> implementation, an attacker can crash the server by sending an initial<br /> packet with an invalid or expired token.<br /> <br /> By default, the client address validation is enabled in the OpenSSL QUIC server<br /> implementation, which makes the default configuration not vulnerable<br /> to this issue. However if the SSL_LISTENER_FLAG_NO_VALIDATE is used with<br /> the SSL_new_listener() call, the address validation is disabled making the<br /> vulnerable code reachable.<br /> <br /> The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this<br /> issue, as the affected code is outside the OpenSSL FIPS module boundary.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* 3.5.0 (including) 3.5.7 (excluding)
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* 3.6.0 (including) 3.6.3 (excluding)
cpe:2.3:a:openssl:openssl:4.0.0:-:*:*:*:*:*:*