CVE-2026-75804 OpenSSL QUIC 连接级流控缺失漏洞
影响恶意对端可耗尽内存,导致拒绝服务
OpenSSL 的 QUIC 协议栈在接收流数据时仅校验流级流控限制,未校验连接级流控限制。远端对端可通过打开多个流并各自保持在流级限制内,绕过连接级窗口约束,使本地栈接收远超预期的数据量。
影响范围
受影响组件为 OpenSSL 的 QUIC 协议栈实现,具体受影响版本范围暂无公开信息。
漏洞详情
该漏洞属于资源分配无限制与节流缺失(CWE-770)。QUIC 会向对端通告流级和连接级两个流控上限,接收方本应在任一上限被突破时以流控错误关闭连接。但存在缺陷的 OpenSSL QUIC 栈只强制流级限制,忽略连接级限制,攻击者只需打开多个流并让每个流保持在流级限制内,即可累积发送大量数据。
利用条件与风险
利用前提是攻击者能与目标建立 QUIC 连接并作为远端对端发送流数据,无需认证即可触发。实战中可导致内存占用从默认约 768 KiB 膨胀至约 100MB,造成内存耗尽型拒绝服务。
修复建议
建议关注 OpenSSL 官方针对 CVE-2026-75804 发布的修复版本并及时升级;临时缓解措施暂无公开信息,可考虑限制 QUIC 连接数或对端来源。
Issue summary: OpenSSL QUIC stack does not enforce connection
level flow control for streams. Remote peers may send more bytes
as long as they fit within the stream flow control limits.
Impact summary: A malicious remote peer may exploit the lack of connection
flow control for streams to make the QUIC stack receive ~100MB of memory
instead of 768 KiB (default flow control window size).
CWE: CWE-770: Allocation of Resources Without Limits or Throttling
Description: The local QUIC stack advertises two flow control limits
to its remote peer: stream flow control limit and connection flow
control limit. The remote peer must follow both limits when transmitting
stream data.
Whenever the local QUIC stack receives a stream frame, it validates
that the size of the received stream frame stays within flow control limits.
If either limit is exceeded (stream level or connection level), then
the QUIC stack must close the connection with a flow control error.
The vulnerable OpenSSL QUIC stack enforces the stream-level but not
the connection-level limit. To exploit the issue, three conditions must be met:
– the remote peer opens several streams
– each stream must stay within the stream-level flow control limit
– there must be no zero-offset byte sent on any of the streams
(to prevent the vulnerable QUIC stack from consuming data).
By meeting the conditions above, the remote peer may make the local stack
allocate 2 x MAX_STREAMS x (stream flow control limit) bytes
of memory. MAX_STREAMS defaults to 100, and the limit applies to both
bidirectional and unidirectional streams, making it 200 in total. The default
flow control window for a stream is 512kB. The remote peer may
force the vulnerable QUIC stack to allocate 100MB of heap per connection.
FIPS impact: no
The FIPS module is not affected as the QUIC implementation is outside of
the OpenSSL FIPS module boundary.