CVE-2026-97031 - Reject malformed ECH outer extension references in crypto/tls
CVE ID :CVE-2026-97031
Published : Oct. 8, 2026, 11:17 p.m. | 29 minutes ago
Description :Multiple ECH outer extension references are not permitted under RFC 9849; previously, a client could send a well-crafted packet that could trigger memory exhaustion in the server process by specifying multiple references. We now reject these as malformed and curb the memory amplification vector as a result.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Oct. 8, 2026, 11:17 p.m. | 29 minutes ago
Description :Multiple ECH outer extension references are not permitted under RFC 9849; previously, a client could send a well-crafted packet that could trigger memory exhaustion in the server process by specifying multiple references. We now reject these as malformed and curb the memory amplification vector as a result.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...