CVE-2026-42764
Severity CVSS v4.0:
Pending analysis
Type:
CWE-476
NULL Pointer Dereference
Publication date:
09/06/2026
Last modified:
23/07/2026
Description
Issue summary: Receiving a QUIC initial packet with an invalid token may<br />
trigger a NULL pointer dereference in the OpenSSL QUIC server with<br />
address validation disabled.<br />
<br />
Impact summary: NULL pointer dereference typically causes abnormal termination<br />
of the affected QUIC server process and a Denial of Service.<br />
<br />
If the address validation is disabled in the OpenSSL QUIC server<br />
implementation, an attacker can crash the server by sending an initial<br />
packet with an invalid or expired token.<br />
<br />
By default, the client address validation is enabled in the OpenSSL QUIC server<br />
implementation, which makes the default configuration not vulnerable<br />
to this issue. However if the SSL_LISTENER_FLAG_NO_VALIDATE is used with<br />
the SSL_new_listener() call, the address validation is disabled making the<br />
vulnerable code reachable.<br />
<br />
The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this<br />
issue, as the affected code is outside the OpenSSL FIPS module boundary.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* | 3.5.0 (including) | 3.5.7 (excluding) |
| cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* | 3.6.0 (including) | 3.6.3 (excluding) |
| cpe:2.3:a:openssl:openssl:4.0.0:-:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://github.com/openssl/openssl/commit/5e3ed291b8af0b03d5d3b9e56a1da69a187e9729
- https://github.com/openssl/openssl/commit/a45a0aba8095682c88ff4fc4a784892b8c6f0677
- https://github.com/openssl/openssl/commit/bf29a458c1a231eca87e384c62b9c2553fa57a91
- https://openssl-library.org/news/secadv/20260609.txt



