CVE-2026-54873 QUIC 内存资源无限制分配漏洞
影响远程对端可长期占用本地 QUIC 栈内存,导致内存耗尽
该漏洞为 QUIC 协议栈在处理数据包缓冲区时的资源分配缺陷(CWE-770)。为减少拷贝操作,QUIC 栈会将流数据保留在包缓冲区中,直到本地接收应用提供缓冲区后才释放引用。攻击者可借此让内存被长时间占用,且占用时长完全由远程对端控制。
影响范围
受影响的具体产品与版本范围暂无公开信息,涉及实现该 QUIC 栈逻辑的组件。
漏洞详情
漏洞类型为资源分配无限制/无节流。成因是 QUIC 栈为提升合法传输效率,将流数据暂存于包缓冲区,仅在数据被拷贝到应用缓冲区后才释放引用。攻击者通过发送特制数据包,可让本地栈分配远超实际数据所需的内存,并延长其占用时间。
利用条件与风险
利用前提是攻击者能与目标建立 QUIC 连接并发送恶意构造的数据包,无需认证。实战中可造成内存资源耗尽,导致服务性能下降或拒绝服务。
修复建议
官方修复方案为 QUIC 栈现按每条流计算并监控内存开销,对单条流帧的内存开销进行限制。临时缓解措施暂无公开信息,建议及时更新到包含该修复的版本。
Issue summary: QUIC process may keep memory for QUIC packet
buffer for much longer period than necessary.
Impact summary: Remote peer can exploit this vulnerability
by sending maliciously crafted packets, making the local
QUIC stack to keep the memory for packet buffers allocated.
The time for which the memory remains allocated is entirely
under the control of the potentially malicious remote peer.
CWE: CWE-770: Allocation of Resources Without Limits or Throttling
Description: To save copy operation from the packet buffer to the
stream reassemble buffer the QUIC stack leaves the stream data
on the packet buffer waiting to be copied to a buffer provided
by the local receiving application. The QUIC stack releases
a reference to the packet buffer only after the data are copied
to the application buffer. This design is more efficient for
legitimate data transfers but enables an attacker to allocate a lot
more memory than actually required by the data kept in the receiving
stream buffer.
To mitigate the vulnerability, the QUIC stack now calculates
and monitors memory overhead for every stream. The memory overhead
for a single stream frame is calculated as a difference between the
size of the whole packet that carries the stream frame and the size
of the stream frame itself. The memory overhead for a single stream
frame is added to the total (cumulative) memory overhead QUIC stack
keeps for each stream. Once the cumulative memory overhead exceeds
64kB, the QUIC stack moves the stream frame data from the packet
buffer to the stream buffer, starting with the next packet received.
FIPS impact: no
The FIPS module is not affected as the QUIC implementation is outside of
the OpenSSL FIPS module boundary.