GHSA-5pg7-f6xv-j6m4 · Severity: high — Issue summary: Receiving a QUIC initial packet with an invalid token may trigger a NULL pointer...
Issue summary: Receiving a QUIC initial packet with an invalid token may trigger a NULL pointer dereference in the OpenSSL QUIC server with address validation disabled. Impact summary: NULL pointer dereference typically causes abnormal termination of the affected QUIC server process and a Denial of Service. If the address validation is disabled in the OpenSSL QUIC server implementation, an attacker can crash the server by sending an initial packet with an invalid or expired token. By default, the client address validation is enabled in the OpenSSL QUIC server implementation, which makes the default configuration not vulnerable to this issue. However if the SSL_LISTENER_FLAG_NO_VALIDATE is used with the SSL_new_listener() call, the address validation is disabled making the vulnerable code reachable. The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.
Conclusion & alert: CVE-2026-42764 is rated Moderate Risk (47/100): CVSS High severity, with low exploitation likelihood (EPSS 0.67%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.04% | 0.67% | +0.62% |
| 2 | 2026-06-10 | — | 0.04% | — |
Full EPSS history (2 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
GHSA-5pg7-f6xv-j6m4 · Severity: high — Issue summary: Receiving a QUIC initial packet with an invalid token may trigger a NULL pointer...
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
unimportant | CVE-2026-42764 unimportant priority: Debian including 1 source packages (openssl), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2026-42764 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2026-42764 |
suse
|
medium | CVE-2026-42764 severity moderate: SUSE including 45 source package names (compat-openssl098, libopenssl-1_0_0-devel, …), 287 product×package rows across 35 product lines (SUSE Liberty Linux 10, SUSE Liberty Linux 9, … (35 product lines)): Known Not Affected 279, Fixed 8. | https://www.suse.com/security/cve/CVE-2026-42764/ |
ubuntu
|
medium | CVE-2026-42764 medium priority: Ubuntu including 5 source packages (edk2, nodejs, openssl, openssl-fips, openssl1.0), 35 status rows across 9 suites (bionic, focal, jammy, noble, questing, resolute, trusty, upstream, xenial): not-affected 20, DNE 6, needs-triage 6, released 2, needed 1. | https://ubuntu.com/security/CVE-2026-42764 |