cve-2026-40898

csaf_suse
Description

SUSE CVE-2026-40898

Timeline
Published
2026-07-11 03:26 UTC
Last Modified
2026-07-11
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References

No references available.

Linked Vulnerabilities

{
  "document": {
    "aggregate_severity": {
      "namespace": "https://www.suse.com/support/security/rating/",
      "text": "moderate"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright 2024 SUSE LLC. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "summary",
        "text": "SUSE CVE-2026-40898",
        "title": "Title"
      },
      {
        "category": "description",
        "text": "quic-go is an implementation of the QUIC protocol in Go. Prior to version 0.59.1, an attacker can cause excessive memory allocation in quic-go's HTTP/3 client and server implementations by sending a QPACK-encoded HEADERS frame that decodes into a large trailer field section with many unique field names and/or large values. The implementation builds an `http.Header` for the corresponding `http.Request` or `http.Response`, while only enforcing limits on the size of the QPACK-compressed HEADERS frame, not on the decoded field section. This can lead to memory exhaustion. This is very similar to CVE-2025-64702. The difference is that this issue uses HTTP trailers, rather than HTTP headers, as the attack vector. A misbehaving or malicious peer can cause a denial-of-service (DoS) attack against quic-go's HTTP/3 servers or clients by triggering excessive memory allocation, potentially leading to crashes or resource exhaustion. This affects both servers and clients due to symmetric header construction. Version 0.59.1 enforces RFC 9114 decoded field section size limits for trailers as well. It incrementally decodes QPACK entries and checks the field section size after each entry, aborting the stream if an entry causes the limit to be exceeded.",
        "title": "Description of the CVE"
      },
      {
        "category": "legal_disclaimer",
        "text": "CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).",
        "title": "Terms of use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://www.suse.com/support/security/contact/",
      "name": "SUSE Product Security Team",
      "namespace": "https://www.suse.com/"
    },
    "references": [
      {
        "category": "external",
        "summary": "CVE-2026-40898",
        "url": "https://www.suse.com/security/cve/CVE-2026-40898"
      },
      {
        "category": "external",
        "summary": "SUSE Security Ratings",
        "url": "https://www.suse.com/support/security/rating/"
      },
      {
        "category": "external",
        "summary": "SUSE Bug 1271244 for CVE-2026-40898",
        "url": "https://bugzilla.suse.com/1271244"
      }
    ],
    "title": "SUSE CVE CVE-2026-40898",
    "tracking": {
      "current_release_date": "2026-07-11T03:26:20Z",
      "generator": {
        "date": "2026-07-11T03:26:20Z",
        "engine": {
          "name": "cve-database.git:bin/generate-csaf-vex.pl",
          "version": "1"
        }
      },
      "id": "CVE-2026-40898",
      "initial_release_date": "2026-07-11T03:26:20Z",
      "revision_history": [
        {
          "date": "2026-07-11T03:26:20Z",
          "number": "2",
          "summary": "vulnerabilities added,references added,severity changed from  to moderate"
        }
      ],
      "status": "interim",
      "version": "2"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "SUSE Linux Enterprise Module for Package Hub 15 SP7",
                "product": {
                  "name": "SUSE Linux Enterprise Module for Package Hub 15 SP7",
                  "product_id": "SUSE Linux Enterprise Module for Package Hub 15 SP7",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:suse:packagehub:15:sp7"
                  }
                }
              },
              {
                "category": "product_name",
                "name": "SUSE Linux Enterprise Server 16.0",
                "product": {
                  "name": "SUSE Linux Enterprise Server 16.0",
                  "product_id": "SUSE Linux Enterprise Server 16.0",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:suse:sles:16:16.0:server"
                  }
                }
              },
              {
                "category": "product_name",
                "name": "SUSE Linux Enterprise Server for SAP applications 16.0",
                "product": {
                  "name": "SUSE Linux Enterprise Server for SAP applications 16.0",
                  "product_id": "SUSE Linux Enterprise Server for SAP applications 16.0",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:suse:sles:16:16.0:server-sap"
                  }
                }
              },
              {
                "category": "product_name",
                "name": "SUSE Manager Client Tools for SLE 15",
                "product": {
                  "name": "SUSE Manager Client Tools for SLE 15",
                  "product_id": "SUSE Manager Client Tools for SLE 15",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:suse:sle-manager-tools:15"
                  }
                }
              },
              {
                "category": "product_name",
                "name": "SUSE Multi-Linux Manager Client Tools for SLE 15",
                "product": {
                  "name": "SUSE Multi-Linux Manager Client Tools for SLE 15",
                  "product_id": "SUSE Multi-Linux Manager Client Tools for SLE 15",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:suse:multi-linux-managertools-sle:15"
                  }
                }
              },
              {
                "category": "product_name",
                "name": "openSUSE Leap 16.0",
                "product": {
                  "name": "openSUSE Leap 16.0",
                  "product_id": "openSUSE Leap 16.0"
                }
              },
              {
                "category": "product_version",
                "name": "golang-github-prometheus-prometheus",
                "product": {
                  "name": "golang-github-prometheus-prometheus",
                  "product_id": "golang-github-prometheus-prometheus",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:a:prometheus:prometheus:*:*:*:*:*:*:*:*",
                    "purl": "pkg:rpm/suse/golang-github-prometheus-prometheus@?upstream=golang-github-prometheus-prometheus.src.rpm"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "SUSE Linux Enterprise"
          }
        ],
        "category": "vendor",
        "name": "SUSE"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "golang-github-prometheus-prometheus as component of SUSE Linux Enterprise Module for Package Hub 15 SP7",
          "product_id": "SUSE Linux Enterprise Module for Package Hub 15 SP7:golang-github-prometheus-prometheus"
        },
        "product_reference": "golang-github-prometheus-prometheus",
        "relates_to_product_reference": "SUSE Linux Enterprise Module for Package Hub 15 SP7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "golang-github-prometheus-prometheus as component of SUSE Linux Enterprise Server 16.0",
          "product_id": "SUSE Linux Enterprise Server 16.0:golang-github-prometheus-prometheus"
        },
        "product_reference": "golang-github-prometheus-prometheus",
        "relates_to_product_reference": "SUSE Linux Enterprise Server 16.0"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "golang-github-prometheus-prometheus as component of SUSE Linux Enterprise Server for SAP applications 16.0",
          "product_id": "SUSE Linux Enterprise Server for SAP applications 16.0:golang-github-prometheus-prometheus"
        },
        "product_reference": "golang-github-prometheus-prometheus",
        "relates_to_product_reference": "SUSE Linux Enterprise Server for SAP applications 16.0"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "golang-github-prometheus-prometheus as component of SUSE Manager Client Tools for SLE 15",
          "product_id": "SUSE Manager Client Tools for SLE 15:golang-github-prometheus-prometheus"
        },
        "product_reference": "golang-github-prometheus-prometheus",
        "relates_to_product_reference": "SUSE Manager Client Tools for SLE 15"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "golang-github-prometheus-prometheus as component of SUSE Multi-Linux Manager Client Tools for SLE 15",
          "product_id": "SUSE Multi-Linux Manager Client Tools for SLE 15:golang-github-prometheus-prometheus"
        },
        "product_reference": "golang-github-prometheus-prometheus",
        "relates_to_product_reference": "SUSE Multi-Linux Manager Client Tools for SLE 15"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "golang-github-prometheus-prometheus as component of openSUSE Leap 16.0",
          "product_id": "openSUSE Leap 16.0:golang-github-prometheus-prometheus"
        },
        "product_reference": "golang-github-prometheus-prometheus",
        "relates_to_product_reference": "openSUSE Leap 16.0"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-40898",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-40898"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "quic-go is an implementation of the QUIC protocol in Go. Prior to version 0.59.1, an attacker can cause excessive memory allocation in quic-go's HTTP/3 client and server implementations by sending a QPACK-encoded HEADERS frame that decodes into a large trailer field section with many unique field names and/or large values. The implementation builds an `http.Header` for the corresponding `http.Request` or `http.Response`, while only enforcing limits on the size of the QPACK-compressed HEADERS frame, not on the decoded field section. This can lead to memory exhaustion. This is very similar to CVE-2025-64702. The difference is that this issue uses HTTP trailers, rather than HTTP headers, as the attack vector. A misbehaving or malicious peer can cause a denial-of-service (DoS) attack against quic-go's HTTP/3 servers or clients by triggering excessive memory allocation, potentially leading to crashes or resource exhaustion. This affects both servers and clients due to symmetric header construction. Version 0.59.1 enforces RFC 9114 decoded field section size limits for trailers as well. It incrementally decodes QPACK entries and checks the field section size after each entry, aborting the stream if an entry causes the limit to be exceeded.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "known_affected": [
          "SUSE Linux Enterprise Module for Package Hub 15 SP7:golang-github-prometheus-prometheus",
          "SUSE Linux Enterprise Server 16.0:golang-github-prometheus-prometheus",
          "SUSE Linux Enterprise Server for SAP applications 16.0:golang-github-prometheus-prometheus",
          "SUSE Manager Client Tools for SLE 15:golang-github-prometheus-prometheus",
          "SUSE Multi-Linux Manager Client Tools for SLE 15:golang-github-prometheus-prometheus",
          "openSUSE Leap 16.0:golang-github-prometheus-prometheus"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-40898",
          "url": "https://www.suse.com/security/cve/CVE-2026-40898"
        },
        {
          "category": "external",
          "summary": "SUSE Security Ratings",
          "url": "https://www.suse.com/support/security/rating/"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1271244 for CVE-2026-40898",
          "url": "https://bugzilla.suse.com/1271244"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-06-04T20:01:16Z",
          "details": "moderate"
        }
      ],
      "title": "CVE-2026-40898"
    }
  ]
}
View JSON API Download JSON