- OpenSSL’s CVE-2026-84782 DTLS flaw can leak heap memory across a connection or crash programs.
- Fixes are public for OpenSSL 4.0.3, 3.6.5, 3.5.9, and 3.4.8; older branches require premium support.
- The bug stems from DTLS handshake resends, and OpenSSL lists no workaround.
- CISA scores it 8.2 CVSS; no exploitation has been reported.
On September 29, OpenSSL disclosed a high-severity flaw in its DTLS implementation that can leak heap memory across a connection or crash the program.
The flaw, tracked as CVE-2026-84782, affects DTLS, the TLS variant used for UDP traffic. DTLS resends handshake messages when no reply arrives before the timer expires, and the leak occurs when a resend starts while a larger message is paused mid-send.
Before the fix, the resend used the paused message’s buffer position instead of returning to the start of the resent message. The message thus carried leftover bytes from the larger message under the wrong handshake label, and reading it could overrun the buffer.
OpenSSL says the mislabeled message can carry heap memory as unencrypted handshake data; if the read reaches unmapped memory, the program crashes. It has not said whether an attacker can trigger the condition and has not reported exploits.
Fixed versions are OpenSSL 4.0.3, 3.6.5, 3.5.9, and 3.4.8. Fixes for the 3.0, 1.1.1, and 1.0.2 branches go only to premium support customers, since OpenSSL 3.0 stopped getting public security fixes on September 7.
The last public 3.0 release was 3.0.22 on August 25; the first non-public 3.0 security release fixes 6 of the 14 flaws disclosed September 29. OpenSSL recommends upgrading to a newer branch or buying paid support.
Meanwhile, Ubuntu patched the flaw on September 29, warning of “incorrect handshake behavior or a denial of service.” Debian fixed it in Debian 13 with DSA-6531-1, though its security tracker still listed Debian 12 as vulnerable as of September 30.
Laurent Gaffie of Secorizon reported the flaw on August 17, and Ryan Hooper developed the fix. CISA assigned a CVSS score of 8.2, rating confidentiality Low and availability High, with no exploitation observed at that time.
OpenSSL’s security policy advises installing High-severity updates as soon as possible, but no workaround exists. The September 29 releases also fixed 13 other flaws, including a Moderate issue in OpenSSL 4.0 and a Low-severity DTLS 1.2 denial-of-service flaw.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
