OpenSSL Patches Nine Vulnerabilities Enabling Remote Denial-of-Service Attacks
ID: d44b45cd-1e43-5142-ba19-4c4994ffd125
STIX ID: report--d44b45cd-1e43-5142-ba19-4c4994ffd125
Feed Name: Cyber Press
OpenSSL published a 25 August 2026 advisory fixing nine vulnerabilities across QUIC, CMS, CMP, DTLS, TLS RPK and AEAD code paths — notable issues include a QUIC double-free (CVE-2026-18798) causing heap corruption and server termination, a CMS deterministic eight-byte out-of-bounds write, DTLS per-connection memory amplification, and several CMP crashes and memory-exhaustion bugs; administrators are advised to prioritize patching internet-facing QUIC/DTLS services and CMP servers, inventory statically linked libraries, and upgrade to the specified OpenSSL releases.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
