PT-2026-47834 · Openssl+4 · Openssl+4

·

CVE-2026-42764

·

Published

2026-06-09

·

Updated

2026-06-22

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenSSL (affected versions not specified)
Description A NULL pointer dereference occurs in the OpenSSL QUIC server when receiving a QUIC initial packet containing an invalid or expired token. This issue is triggered specifically when address validation is disabled, which can be achieved by using the SSL LISTENER FLAG NO VALIDATE flag within the SSL new listener() function. A NULL pointer dereference is a condition where the software attempts to read or write to a memory location that is null, typically resulting in the abnormal termination of the process and a Denial of Service.
Recommendations Avoid using the SSL LISTENER FLAG NO VALIDATE flag in the SSL new listener() function to ensure client address validation remains enabled. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:25237
ALSA-2026:25239
CVE-2026-42764
OPENSUSE-SU-2026:11023-1
OPENSUSE-SU-2026:21005-1
RHSA-2026:25237
RHSA-2026:25239
SUSE-SU-2026:22251-1
SUSE-SU-2026:22315-1
USN-8414-1

Affected Products

Freebsd
Linuxmint
Openssl
Rocky Linux
Ubuntu