OpenSSL Security Update Advisory (CVE-2026-14456)

OpenSSL Security Update Advisory (CVE-2026-14456)
  • A security update addressing a vulnerability in OpenSSL products has been released.
  • Affected versions include OpenSSL 3.5.0 Through 3.5.7, 3.6.0 Through 3.6.3, And 4.0.0 Through 4.0.1.
  • The vulnerability addressed is CVE-2026-14456, a denial-of-service vulnerability caused by an unlimited memory increase in the QUIC (Quick Communication Inter-Network Protocol) server receive channel queue.
  • A patch for this vulnerability has been provided through the latest update.
  • Affected versions are OpenSSL 3.5.8 Or later, 3.6.4 Or later, and 4.0.2 Or later.
  • Alternatively, the systems must have commits 08e7756, 4084152, and f2f1465 applied, respectively.
  • It is recommended to update to the latest version with the Vulnerability Patch, following the instructions on the reference site.