Issue summary: Receiving a QUIC initial packet with an invalid token may trigger a NULL pointer dereference in the OpenSSL QUIC server with address validation disabled.
Impact summary: NULL pointer dereference typically causes abnormal termination of the affected QUIC server process and a Denial of Service.
If the address validation is disabled in the OpenSSL QUIC server implementation, an attacker can crash the server by sending an initial packet with an invalid or expired token.
By default, the client address validation is enabled in the OpenSSL QUIC server implementation, which makes the default configuration not vulnerable to this issue. However if the SSL_LISTENER_FLAG_NO_VALIDATE is used with the SSL_new_listener() call, the address validation is disabled making the vulnerable code reachable.
The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade opensslUpgrade openssl-develUpgrade openssl-perlUpgrade openssl-libs | Jun 16, 2026 | Jun 11, 2026 |
| Alpine Linux | — | Upgrade openssl | Jun 18, 2026 | Jun 9, 2026 |
| Amazon_linux_2023 | — | Upgrade openssl-debugsourceUpgrade openssl-snapsafe-libs-debuginfoUpgrade openssl-fips-provider-latest-debuginfoUpgrade opensslUpgrade openssl-debuginfoUpgrade openssl-fips-provider-latestUpgrade openssl-libs-debuginfoUpgrade openssl-snapsafe-libsUpgrade openssl-develUpgrade openssl-perlUpgrade openssl-libs | Jun 23, 2026 | Jun 9, 2026 |
| Debian | — | Upgrade openssl | Jul 23, 2026 | Jul 23, 2026 |
| Freebsd | — | Upgrade openssl36Upgrade openssl35Upgrade openssl40Upgrade opensslUpgrade openssl111Upgrade openssl34Upgrade FreeBSD | Jun 15, 2026 | Jun 10, 2026 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Jun 10, 2026 | Jun 9, 2026 |
| Oracle Missing Cpu Jul 2026 | — | Apply the July 2026 Critical Patch Update (CPU) for Oracle Database | Jul 22, 2026 | Jun 9, 2026 |
| Redhat_linux | — | Upgrade openssl-debuginfoNo solution existsUpgrade openssl-debugsourceUpgrade openssl-libs-debuginfoUpgrade opensslUpgrade openssl-perlUpgrade openssl-develUpgrade openssl-libs | Jun 17, 2026 | Jun 9, 2026 |
| Rocky_linux | — | Upgrade openssl-libs-debuginfoUpgrade openssl-debugsourceUpgrade openssl-develUpgrade openssl-libsUpgrade openssl-debuginfoUpgrade opensslUpgrade openssl-perl | Jun 17, 2026 | Jun 13, 2026 |
| Ubuntu | — | Upgrade libssl3Upgrade opensslUpgrade libssl3t64 | Jun 16, 2026 | Jun 9, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jun 18, 2026 | Jun 9, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub