Dev News Daily ENDE

Eleven OpenSSL CVEs fixed, from QUIC memory bugs to SM2 timing leaks

Canonical published Ubuntu Security Notice USN-8847-1 on 29 September, fixing several OpenSSL vulnerabilities in Ubuntu 26.04 LTS, 24.04 LTS and 22.04 LTS. The notice lists eleven CVEs, from CVE-2026-35189 to CVE-2026-84784.

Most are denial-of-service bugs. OpenSSL mishandled certain certificate revocation list distribution point names, which could exhaust memory. In QUIC it mishandled amplification credit accounting for unvalidated peers, did not correctly enforce connection-level flow control for streams, and could consume excessive memory processing RETIRE_CONNECTION_ID frames. In DTLS, undersized AEAD records in DTLS 1.2 were mishandled before authentication and handshake retransmission could misbehave. A NULL pointer in CMP client revocation response processing could crash the process. A flaw in SSL context switching during a TLS handshake could cause an out-of-bounds read, leading to a crash or information disclosure.

Three issues are timing side channels that could leak sensitive information: scalar multiplication for non-NIST elliptic curves, SM2 scalar multiplication on ARM64 and RISC-V, and SM2 signature generation.

Several of the issues, including the QUIC ones, the SM2 ARM64/RISC-V side channel and the context-switching read, affected only Ubuntu 26.04 LTS. The fix is a standard package update, and the notice says a reboot is needed to apply all changes.

Eleven OpenSSL CVEs fixed, from QUIC memory bugs to SM2 timing leaks
Eleven OpenSSL CVEs fixed, from QUIC memory bugs to SM2 timing leaks — Dev News Daily

Why it matters

OpenSSL sits under almost every network service on a Linux host, so a batch like this is a routine but not optional update. Teams that enabled QUIC on 26.04 have the most exposure; on older LTS releases the list is shorter, but the side-channel and parsing fixes still apply.

Primary source
Ubuntu Security Notices
https://ubuntu.com/security/notices/USN-8847-1