AZL-105525

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105525.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-105525
Upstream
Published
2026-09-29T16:17:07Z
Modified
2026-10-04T05:34:07Z
Summary
CVE-2026-42772 affecting package kata-containers 4.1.0.kata0-1
Details

Issue summary: The QUIC stream reassembly algorithm performance deteriorates progressively as packets are arriving out of order. The worst case has a quadratic complexity proportional to the number of stream frames kept in the buffer for the received stream data.

Impact summary: A remote QUIC peer that completes the handshake can create a connection-scoped CPU pressure and potentially a Denial of Service using compliant STREAM frames inside the advertised receive window, with low attacker bandwidth.

CWE: CWE-407: Inefficient Algorithmic Complexity

Description: OpenSSL manages received QUIC stream fragments using a doubly-linked list. While it optimizes for append operations (at the end of the list), it falls back to a head-to-tail linear search for any fragment that does not immediately follow the current tail.

By manipulating the sequence of offsets, an attacker can force the server to perform O(n^2) operations, consuming excessive CPU time for the QUIC process.

FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary.

References

Affected packages

Azure Linux:3 / kata-containers

Package

Name
kata-containers
Purl
pkg:rpm/azure-linux/kata-containers

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
4.1.0.kata0-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105525.json"