RHSA-2026:56097HighCVSS 7.5
Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update
🔗 CVE IDs covered (2)
📋 Description
CVE-2026-14456 — openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server CVE-2026-54876 — openssl: OpenSSL: Memory leak leads to Denial of Service in OCSP response checking
🎯 Affected products4
- Red Hat Hardened Images
- openssl-main@aarch64 as a component of Red Hat Hardened Images
- openssl-main@src as a component of Red Hat Hardened Images
- openssl-main@x86_64 as a component of Red Hat Hardened Images
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Workaround: Rate-limit or firewall inbound QUIC (UDP 443) traffic at the network level to reduce exposure. If QUIC server functionality is not required, disable it and use TLS over TCP instead. The upstream fix introduces a default limit of 256 pending connections, configurable via SSL_set_value_uint(3ossl).
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2026:56097
- externalhttps://access.redhat.com/security/cve/CVE-2026-14456
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://images.redhat.com/
- externalhttps://access.redhat.com/security/cve/CVE-2026-54876
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_56097.json