CVE-2025-54939

LiteSpeed QUIC (LSQUIC) Library before 4.3.1 has an lsquic_engine_packet_in memory leak.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:litespeedtech:litespeed_web_adc:*:*:*:*:*:*:*:*
cpe:2.3:a:litespeedtech:litespeed_web_server:*:*:*:*:*:*:*:*
cpe:2.3:a:litespeedtech:lsquic:*:*:*:*:*:*:*:*
cpe:2.3:a:litespeedtech:openlitespeed:*:*:*:*:*:*:*:*

History

27 Aug 2025, 15:52

Type Values Removed Values Added
First Time Litespeedtech lsquic
CPE cpe:2.3:a:litespeedtech:lsquic:*:*:*:*:*:*:*:*

27 Aug 2025, 15:04

Type Values Removed Values Added
CPE cpe:2.3:a:litespeedtech:litespeed_web_adc:*:*:*:*:*:*:*:*
cpe:2.3:a:litespeedtech:litespeed_web_server:*:*:*:*:*:*:*:*
cpe:2.3:a:litespeedtech:openlitespeed:*:*:*:*:*:*:*:*
First Time Litespeedtech litespeed Web Server
Litespeedtech litespeed Web Adc
Litespeedtech
Litespeedtech openlitespeed
CWE CWE-401
References () https://blog.litespeedtech.com/2025/08/18/litespeed-security-update/ - () https://blog.litespeedtech.com/2025/08/18/litespeed-security-update/ - Vendor Advisory
References () https://github.com/litespeedtech/lsquic/blob/70486141724f85e97b08f510673e29f399bbae8f/CHANGELOG#L1-L3 - () https://github.com/litespeedtech/lsquic/blob/70486141724f85e97b08f510673e29f399bbae8f/CHANGELOG#L1-L3 - Release Notes
References () https://github.com/litespeedtech/lsquic/commit/4cd9252e77fb4a36b572e2167a84067d603d3b23 - () https://github.com/litespeedtech/lsquic/commit/4cd9252e77fb4a36b572e2167a84067d603d3b23 - Release Notes
References () https://www.imperva.com/blog/quic-leak-cve-2025-54939-new-high-risk-pre-handshake-remote-denial-of-service-in-lsquic-quic-implementation/ - () https://www.imperva.com/blog/quic-leak-cve-2025-54939-new-high-risk-pre-handshake-remote-denial-of-service-in-lsquic-quic-implementation/ - Exploit, Third Party Advisory

20 Aug 2025, 20:15

Type Values Removed Values Added
References
  • () https://blog.litespeedtech.com/2025/08/18/litespeed-security-update/ -

19 Aug 2025, 03:15

Type Values Removed Values Added
References
  • () https://www.imperva.com/blog/quic-leak-cve-2025-54939-new-high-risk-pre-handshake-remote-denial-of-service-in-lsquic-quic-implementation/ -

04 Aug 2025, 15:06

Type Values Removed Values Added
Summary
  • (es) La librería LiteSpeed QUIC (LSQUIC) anterior a 4.3.1 tiene una pérdida de memoria lsquic_engine_packet_in.

01 Aug 2025, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-01 06:15

Updated : 2025-08-27 15:52


NVD link : CVE-2025-54939

Mitre link : CVE-2025-54939

CVE.ORG link : CVE-2025-54939


JSON object : View

Products Affected

litespeedtech

  • litespeed_web_server
  • openlitespeed
  • litespeed_web_adc
  • lsquic
CWE
CWE-770

Allocation of Resources Without Limits or Throttling

CWE-401

Missing Release of Memory after Effective Lifetime