Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update
This update includes the following RPMs: openssl: * openssl-3.5.6-0.5.hum1 (aarch64, x86_64) * openssl-config-fips-3.5.6-0.5.hum1 (aarch64, x86_64) * openssl-devel-3.5.6-0.5.hum1 (aarch64, x86_64) * openssl-devel-engine-3.5.6-0.5.hum1 (aarch64, x86_64) * openssl-fips-provider-upstream-3.5.6-0.5.hum1 (aarch64, x86_64) * openssl-libs-3.5.6-0.5.hum1 (aarch64, x86_64) * openssl-perl-3.5.6-0.5.hum1 (aarch64, x86_64) * openssl-3.5.6-0.5.hum1.src (src) Security Fix(es): openssl: * CVE-2026-14456
AI Analysis
Technical Summary
CVE-2026-14456 is a denial of service vulnerability in OpenSSL's QUIC server implementation present in version 3.5.x. An attacker can send a large number of QUIC Initial packets to the server, causing it to allocate and queue new incoming channels without limit, resulting in unbounded memory consumption. This leads to a denial of service condition by making the QUIC listener unavailable. The vulnerability affects Red Hat Hardened Images shipping OpenSSL 3.5.x, specifically versions prior to 3.6.0. Systems running earlier OpenSSL versions without QUIC support are not affected. The vulnerability requires the QUIC server listener to be explicitly enabled to be exploitable. Red Hat has issued a security advisory and released patched RPMs including openssl-3.5.6-0.5.hum1 to fix this issue.
Potential Impact
The vulnerability allows remote attackers to cause unbounded memory growth on affected OpenSSL QUIC servers, leading to denial of service by exhausting server memory and making the QUIC listener unavailable. There is no impact on confidentiality or integrity. The flaw requires the QUIC server listener to be enabled and affects network-exposed services listening on UDP port 443. Systems not running the QUIC server or not listening on UDP 443 are not affected.
Mitigation Recommendations
Red Hat has released fixed OpenSSL packages (openssl-3.5.6-0.5.hum1) that address this vulnerability and should be applied promptly. Until patched, administrators should verify if any service is listening on UDP port 443 for QUIC traffic. If so, rate-limit or firewall inbound UDP 443 traffic to slow or block QUIC Initial packets. If QUIC/HTTP3 is not required, disable the QUIC server listener entirely to eliminate exposure. Application owners can also adjust the SSL_VALUE_QUIC_MAX_PENDING_CONNS parameter if the default limit is too high. Following these steps will mitigate the risk until the update is applied.
Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update
Description
This update includes the following RPMs: openssl: * openssl-3.5.6-0.5.hum1 (aarch64, x86_64) * openssl-config-fips-3.5.6-0.5.hum1 (aarch64, x86_64) * openssl-devel-3.5.6-0.5.hum1 (aarch64, x86_64) * openssl-devel-engine-3.5.6-0.5.hum1 (aarch64, x86_64) * openssl-fips-provider-upstream-3.5.6-0.5.hum1 (aarch64, x86_64) * openssl-libs-3.5.6-0.5.hum1 (aarch64, x86_64) * openssl-perl-3.5.6-0.5.hum1 (aarch64, x86_64) * openssl-3.5.6-0.5.hum1.src (src) Security Fix(es): openssl: * CVE-2026-14456
Affected software
pkg:github/openssl/opensslRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-14456 is a denial of service vulnerability in OpenSSL's QUIC server implementation present in version 3.5.x. An attacker can send a large number of QUIC Initial packets to the server, causing it to allocate and queue new incoming channels without limit, resulting in unbounded memory consumption. This leads to a denial of service condition by making the QUIC listener unavailable. The vulnerability affects Red Hat Hardened Images shipping OpenSSL 3.5.x, specifically versions prior to 3.6.0. Systems running earlier OpenSSL versions without QUIC support are not affected. The vulnerability requires the QUIC server listener to be explicitly enabled to be exploitable. Red Hat has issued a security advisory and released patched RPMs including openssl-3.5.6-0.5.hum1 to fix this issue.
Potential Impact
The vulnerability allows remote attackers to cause unbounded memory growth on affected OpenSSL QUIC servers, leading to denial of service by exhausting server memory and making the QUIC listener unavailable. There is no impact on confidentiality or integrity. The flaw requires the QUIC server listener to be enabled and affects network-exposed services listening on UDP port 443. Systems not running the QUIC server or not listening on UDP 443 are not affected.
Mitigation Recommendations
Red Hat has released fixed OpenSSL packages (openssl-3.5.6-0.5.hum1) that address this vulnerability and should be applied promptly. Until patched, administrators should verify if any service is listening on UDP port 443 for QUIC traffic. If so, rate-limit or firewall inbound UDP 443 traffic to slow or block QUIC Initial packets. If QUIC/HTTP3 is not required, disable the QUIC server listener entirely to eliminate exposure. Application owners can also adjust the SSL_VALUE_QUIC_MAX_PENDING_CONNS parameter if the default limit is too high. Following these steps will mitigate the risk until the update is applied.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-9x89-v382-mjh7
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-14456"]
Threat ID: 6a7e0352bf8831d5398f7150
Added to database: 08/13/2026, 17:48:02 UTC
Last enriched: 09/24/2026, 08:29:19 UTC
Last updated: 09/27/2026, 20:19:25 UTC
Views: 66
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.