Commit 4ae4f4d127 for openssl.org
commit 4ae4f4d127b564e6446791d6a799918d3c7095c1
Author: Alexandr Nedvedicky <sashan@openssl.org>
Date: Thu Sep 3 14:22:40 2026 +0200
CVE-2026-75804 QUIC connection-level flow control not enforced, remote memory exhaustion
Function ossl_quic_rxfc_get_error() must also report flow control violation
error for connection level not just for stream level. Ignoring connection
level error prevents QUIC stack to enforce flow control.
Fixes CVE-2026-75804
Reviewed-by: Andrew Dinh <andrewd@openssl.org>
Reviewed-by: Tomas Mraz <tomas@openssl.foundation>
Merge-date: Tue Sep 29 10:44:28 2026
diff --git a/ssl/quic/quic_fc.c b/ssl/quic/quic_fc.c
index 1691d4d69e..bda6e5b5db 100644
--- a/ssl/quic/quic_fc.c
+++ b/ssl/quic/quic_fc.c
@@ -393,8 +393,17 @@ int ossl_quic_rxfc_get_error(QUIC_RXFC *rxfc, int clear)
{
int r = rxfc->error_code;
- if (clear)
+ if (r == OSSL_QUIC_ERR_NO_ERROR && rxfc->parent != NULL)
+ r = rxfc->parent->error_code;
+
+ /*
+ * The clear argument is used for testing only.
+ */
+ if (clear) {
rxfc->error_code = 0;
+ if (rxfc->parent != NULL)
+ rxfc->parent->error_code = 0;
+ }
return r;
}