LiteSpeed QUIC (LSQUIC) Library before 4.3.1 has an lsquic_engine_packet_in memory leak.
References
Configurations
Configuration 1 (hide)
|
History
27 Aug 2025, 15:52
Type | Values Removed | Values Added |
---|---|---|
First Time |
Litespeedtech lsquic
|
|
CPE | cpe:2.3:a:litespeedtech:lsquic:*:*:*:*:*:*:*:* |
27 Aug 2025, 15:04
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:litespeedtech:litespeed_web_adc:*:*:*:*:*:*:*:* cpe:2.3:a:litespeedtech:litespeed_web_server:*:*:*:*:*:*:*:* cpe:2.3:a:litespeedtech:openlitespeed:*:*:*:*:*:*:*:* |
|
First Time |
Litespeedtech litespeed Web Server
Litespeedtech litespeed Web Adc Litespeedtech Litespeedtech openlitespeed |
|
CWE | CWE-401 | |
References | () https://blog.litespeedtech.com/2025/08/18/litespeed-security-update/ - Vendor Advisory | |
References | () https://github.com/litespeedtech/lsquic/blob/70486141724f85e97b08f510673e29f399bbae8f/CHANGELOG#L1-L3 - Release Notes | |
References | () https://github.com/litespeedtech/lsquic/commit/4cd9252e77fb4a36b572e2167a84067d603d3b23 - Release Notes | |
References | () https://www.imperva.com/blog/quic-leak-cve-2025-54939-new-high-risk-pre-handshake-remote-denial-of-service-in-lsquic-quic-implementation/ - Exploit, Third Party Advisory |
20 Aug 2025, 20:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
19 Aug 2025, 03:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
04 Aug 2025, 15:06
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
01 Aug 2025, 06:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-08-01 06:15
Updated : 2025-08-27 15:52
NVD link : CVE-2025-54939
Mitre link : CVE-2025-54939
CVE.ORG link : CVE-2025-54939
JSON object : View
Products Affected
litespeedtech
- litespeed_web_server
- openlitespeed
- litespeed_web_adc
- lsquic