Commit 4ae4f4d127 for openssl.org

commit 4ae4f4d127b564e6446791d6a799918d3c7095c1
Author: Alexandr Nedvedicky <sashan@openssl.org>
Date:   Thu Sep 3 14:22:40 2026 +0200

    CVE-2026-75804 QUIC connection-level flow control not enforced, remote memory exhaustion

    Function ossl_quic_rxfc_get_error() must also report flow control violation
    error for connection level not just for stream level. Ignoring connection
    level error prevents QUIC stack to enforce flow control.

    Fixes CVE-2026-75804

    Reviewed-by: Andrew Dinh <andrewd@openssl.org>
    Reviewed-by: Tomas Mraz <tomas@openssl.foundation>
    Merge-date: Tue Sep 29 10:44:28 2026

diff --git a/ssl/quic/quic_fc.c b/ssl/quic/quic_fc.c
index 1691d4d69e..bda6e5b5db 100644
--- a/ssl/quic/quic_fc.c
+++ b/ssl/quic/quic_fc.c
@@ -393,8 +393,17 @@ int ossl_quic_rxfc_get_error(QUIC_RXFC *rxfc, int clear)
 {
     int r = rxfc->error_code;

-    if (clear)
+    if (r == OSSL_QUIC_ERR_NO_ERROR && rxfc->parent != NULL)
+        r = rxfc->parent->error_code;
+
+    /*
+     * The clear argument is used for testing only.
+     */
+    if (clear) {
         rxfc->error_code = 0;
+        if (rxfc->parent != NULL)
+            rxfc->parent->error_code = 0;
+    }

     return r;
 }