skip to content
emilloc
esc
back
tags
c
CVE
18798
double free in openssl's quic channel bind path
25 aug 2026
· CVE-2026-18798 · cve, openssl, quic, c · 6 min
a pointer in OpenSSL's QUIC bind path does double duty as a return value and an ownership handoff. when a bind fails, it's left unwritten, so the caller assumes the channel never took the QRX and frees it again after the channel already did. fixed in 3.5.8 / 3.6.4 / 4.0.2.