Skip to main content
EPSS 0.7%top 48%

Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update

0
High
Published: 08/18/2026 (08/18/2026, 10:51:22 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

This update includes the following RPMs: openssl: * openssl-3.5.6-0.5.hum1 (aarch64, x86_64) * openssl-config-fips-3.5.6-0.5.hum1 (aarch64, x86_64) * openssl-devel-3.5.6-0.5.hum1 (aarch64, x86_64) * openssl-devel-engine-3.5.6-0.5.hum1 (aarch64, x86_64) * openssl-fips-provider-upstream-3.5.6-0.5.hum1 (aarch64, x86_64) * openssl-libs-3.5.6-0.5.hum1 (aarch64, x86_64) * openssl-perl-3.5.6-0.5.hum1 (aarch64, x86_64) * openssl-3.5.6-0.5.hum1.src (src) Security Fix(es): openssl: * CVE-2026-14456

Affected software

GitHub Actionsmore threats →ai
openssl/openssl
pkg:github/openssl/openssl
Affected versions
=3.5.0<3.6.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/24/2026, 08:29:19 UTC

Technical Analysis

CVE-2026-14456 is a denial of service vulnerability in OpenSSL's QUIC server implementation present in version 3.5.x. An attacker can send a large number of QUIC Initial packets to the server, causing it to allocate and queue new incoming channels without limit, resulting in unbounded memory consumption. This leads to a denial of service condition by making the QUIC listener unavailable. The vulnerability affects Red Hat Hardened Images shipping OpenSSL 3.5.x, specifically versions prior to 3.6.0. Systems running earlier OpenSSL versions without QUIC support are not affected. The vulnerability requires the QUIC server listener to be explicitly enabled to be exploitable. Red Hat has issued a security advisory and released patched RPMs including openssl-3.5.6-0.5.hum1 to fix this issue.

Potential Impact

The vulnerability allows remote attackers to cause unbounded memory growth on affected OpenSSL QUIC servers, leading to denial of service by exhausting server memory and making the QUIC listener unavailable. There is no impact on confidentiality or integrity. The flaw requires the QUIC server listener to be enabled and affects network-exposed services listening on UDP port 443. Systems not running the QUIC server or not listening on UDP 443 are not affected.

Mitigation Recommendations

Red Hat has released fixed OpenSSL packages (openssl-3.5.6-0.5.hum1) that address this vulnerability and should be applied promptly. Until patched, administrators should verify if any service is listening on UDP port 443 for QUIC traffic. If so, rate-limit or firewall inbound UDP 443 traffic to slow or block QUIC Initial packets. If QUIC/HTTP3 is not required, disable the QUIC server listener entirely to eliminate exposure. Application owners can also adjust the SSL_VALUE_QUIC_MAX_PENDING_CONNS parameter if the default limit is too high. Following these steps will mitigate the risk until the update is applied.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-9x89-v382-mjh7
Osv Schema Version
1.4.0
Aliases
["CVE-2026-14456"]

Threat ID: 6a7e0352bf8831d5398f7150

Added to database: 08/13/2026, 17:48:02 UTC

Last enriched: 09/24/2026, 08:29:19 UTC

Last updated: 09/27/2026, 20:19:25 UTC

Views: 66

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

NVD DatabaseMITRE CVEReference 1Reference 2Reference 3Reference 4Reference 5Reference 6Reference 7https://access.redhat.com/errata/RHSA-2026:56097https://access.redhat.com/security/cve/CVE-2026-14456https://access.redhat.com/security/updates/classification/https://images.redhat.com/Canonical URLhttps://access.redhat.com/security/cve/CVE-2026-54876Reference 14Reference 15Reference 16Reference 17Reference 18Reference 19Reference 20Reference 21Reference 22Reference 23WID-SEC-W-2026-2843 - CSAF VersionWID-SEC-2026-2843 - Portal VersionOpenSSL Vulnerability vom 2026-08-13GitHub Security Advisory GHSA-9x89-v382-mjh7 vom 2026-08-13Debian Security Advisory DSA-6465 vom 2026-08-25Ubuntu Security Notice USN-8678-2 vom 2026-08-26openSUSE Security Update OPENSUSE-SU-2026:11623-1 vom 2026-08-30CVE-2026-14456 Unbounded Memory Growth in QUIC Server Incoming Channel Queue - VEXMicrosoft Support LifecycleCommon Vulnerability Scoring Systemhttps://access.redhat.com/errata/RHSA-2026:67154https://access.redhat.com/security/updates/classification/#important251534825175592517560251756125175622517564251756525175662517570RHEL-212362Canonical URLSUSE ratingsURL of this CSAF noticeSUSE Bug 1266343SUSE Bug 1274774SUSE Bug 1274777SUSE Bug 1274788SUSE Bug 1274790SUSE Bug 1274791SUSE Bug 1274792SUSE Bug 1274795SUSE Bug 1274796SUSE Bug 1274797SUSE Bug 1274798SUSE Bug 1275837SUSE CVE CVE-2026-14456 pageSUSE CVE CVE-2026-14457 pageSUSE CVE CVE-2026-18798 pageSUSE CVE CVE-2026-34181 pageSUSE CVE CVE-2026-54874 pageSUSE CVE CVE-2026-63072 pageSearch on Google

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses