USN-8678-1: OpenSSL vulnerabilities
It was discovered that OpenSSL incorrectly handled the QUIC server incoming channel queue. A remote attacker could possibly use this issue to cause OpenSSL to use excessive resources, leading to a denial of service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-14456) It was discovered that OpenSSL incorrectly handled signature algorithm selection when using Raw Public Keys. A remote attacker could possibly use this issue to cause OpenSSL to crash, resulting in a denial of service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-14457) It was discovered that OpenSSL incorrectly handled QUIC INITIAL packet processing. A remote attacker could possibly use this issue to cause OpenSSL to crash, resulting in a denial of service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-18798) It was discovered that OpenSSL incorrectly handled buffering of DTLS records for a future epoch. A remote attacker could possibly use this issue to cause OpenSSL to use excessive resources, leading to a denial of service. (CVE-2026-54874) It was discovered that OpenSSL incorrectly handled CMS key unwrapping. A remote attacker could possibly use this issue to cause a heap buffer overflow, leading to a denial of service or arbitrary code execution. (CVE-2026-63072) It was discovered that OpenSSL incorrectly validated the sender distinguished name in CMP response messages. A remote attacker could possibly use this issue to cause OpenSSL to crash, resulting in a denial of service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-63073) It was discovered that OpenSSL incorrectly limited the growth of an internal certificate cache used during CMP operations. A remote attacker could possibly use this issue to cause OpenSSL to use excessive resources, leading to a denial of service. (CVE-2026-63074) It was discovered that OpenSSL incorrectly handled QUIC ACK-only packet retention. A remote attacker could possibly use this issue to cause OpenSSL to use excessive resources, leading
CSIRTS triage
- What
- Multiple denial of service vulnerabilities in OpenSSL QUIC and DTLS handling allow remote attackers to exhaust resources or crash the service through malformed packets.
- Who is affected
- Ubuntu 26.04 LTS systems and applications using affected OpenSSL versions with QUIC or DTLS functionality enabled.
- Urgency
- Moderate; allows denial of service but not code execution; no active exploitation reported.
- Action
- Apply the USN-8678-1 OpenSSL security update to affected Ubuntu systems.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch OpenSSL
Get an email when a new OpenSSL advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://ubuntu.com/security/notices/USN-8678-1
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-144560.61% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 47% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-14456 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-14457 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-18798 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-54874 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-63072 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-63073 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-63074 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-63075 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-63076 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-75803 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownCVE-2026-75803: Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report su…nvd
- highCVE-2026-63076: Issue summary: OpenSSL CMP password based protection verification only checks whether the prot…nvd
- highCVE-2026-63075: Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly sends ack-elici…nvd
- mediumCVE-2026-63074: Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificate…nvd
- unknownCVE-2026-63073: Issue summary: OpenSSL CMP response validation passed an unexpected response sender distinguis…nvd
- highCVE-2026-63072: Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the…nvd
- highCVE-2026-54874: Issue summary: Receiving a DTLS record for a future epoch while a handshake is in progress cau…nvd
- highCVE-2026-18798: Issue summary: QUIC server may double free QRX (QUIC record layer RX) object when channel crea…nvd
- highCVE-2026-14457: Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs) enabled…nvd
- unknownDSA-6465-1 openssl - security updatedebian
- medium[NEW] [medium] OpenSSL: Vulnerability enables denial of servicecert-bund
- unknownVulnerability in OpenSSL (August 14, 2026)cert-fr-avis
More from Ubuntu Security Notices
- unknownUSN-8659-4: Linux kernel (Oracle) vulnerability2026-08-26
- unknownUSN-8666-2: Linux kernel (Azure) vulnerabilities2026-08-25
- unknownUSN-8630-5: Linux kernel (Raspberry Pi) vulnerabilities2026-08-25
- unknownUSN-8658-3: Linux kernel vulnerabilities2026-08-25
- unknownUSN-8643-4: Linux kernel vulnerabilities2026-08-25