A security update addressing a vulnerability in OpenSSL products has been released.
Affected versions include OpenSSL 3.5.0 Through 3.5.7, 3.6.0 Through 3.6.3, And 4.0.0 Through 4.0.1.
The vulnerability addressed is CVE-2026-14456, a denial-of-service vulnerability caused by an unlimited memory increase in the QUIC (Quick Communication Inter-Network Protocol) server receive channel queue.
A patch for this vulnerability has been provided through the latest update.
Affected versions are OpenSSL 3.5.8 Or later, 3.6.4 Or later, and 4.0.2 Or later.
Alternatively, the systems must have commits 08e7756, 4084152, and f2f1465 applied, respectively.
It is recommended to update to the latest version with the Vulnerability Patch, following the instructions on the reference site.