CVE-2025-54939
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
LiteSpeed QUIC (LSQUIC) Library before 4.3.1 has an lsquic_engine_packet_in memory leak.
Affected (4)
Products: Litespeedtech: Litespeed Web Adc, Litespeed Web Server, Lsquic, Openlitespeed
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.3.1 | |
| Before 6.3.4 | |
| Before 4.3.1 | |
| Before 1.8.4 |
Related CWEs
CWE-401
Missing Release of Memory after Effective Lifetime
The product does not sufficiently track and release allocated memory after it has been used, which slowly consumes remaining memory.
CWE-770
Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.
References (4)
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Release Notes
Source: cve@mitre.org
Release Notes
Source: cve@mitre.org
ExploitThird Party Advisory
Timeline
No history available yet.