Mastodon Mastodon Mastodon Mastodon

OpenSSL patches high-severity DTLS vulnerability that leads to heap memory disclosure

Photo of author

CyberSecureFox Editorial Team

Published:

On 29 September, the OpenSSL project released security updates that fix the high-severity CVE-2026-84782 vulnerability in the DTLS message retransmission mechanism. The bug allows the contents of a process’s heap memory to be sent to a remote party as plaintext handshake data or to trigger an application crash. The vulnerability affects all main OpenSSL branches — from 1.0.2 through 4.0 — but only applications that use OpenSSL specifically for DTLS connections. Regular TLS deployments are not affected. Fixes are available in OpenSSL versions 4.0.3, 3.6.5, 3.5.9 and 3.4.8, as well as in Ubuntu and Debian packages.

Vulnerability mechanism

DTLS (Datagram Transport Layer Security) is a variant of TLS for UDP traffic described in RFC 9147. It is used, in particular, to secure WebRTC data channels and to establish encryption keys for internet calls. Since UDP does not guarantee delivery, DTLS implements its own retransmission mechanism: if a response to a handshake message is not received before the timer expires, the message is sent again.

DTLS splits large handshake messages into fragments, each of which fits into a single UDP datagram. If the connection cannot temporarily accept data, sending is paused halfway through the message. According to the description in the CISA ADP entry, the problem arises when the retransmission timer fires while writing a larger handshake message is paused midway. Before the fix, the retransmission code used the current position of the paused message in the buffer instead of returning to the beginning of the message being resent. As a result, the retransmitted message received an incorrect label, and its body contained the remaining bytes from the larger message’s buffer, with reads potentially going out of bounds.

This leads to two consequences: the contents of heap memory can be sent to the remote party as plaintext handshake data, and if the read reaches an unmapped memory region, the process crashes.

Severity assessment

According to the OpenSSL 3.4.8 release description, the OpenSSL project rates CVE-2026-84782 as a High-severity vulnerability — one step below Critical on its own scale. CISA ADP assigned a rating of CVSS 3.1 — 8.2 (High) with the vector AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H, indicating low impact on confidentiality and high impact on availability. It is important to note that OpenSSL does not use CVSS to determine its own severity ratings and points out that assessments from external organizations may differ significantly.

At the time the entry was published on 29 September, CISA listed the exploitation status as “none”. No independent public reports of exploitation of the vulnerability had been found. At the same time, OpenSSL did not clarify whether an attacker can deliberately trigger a retransmission at the moment when message writing is paused.

Impact scope

The practical blast radius is narrower than the number of affected versions might suggest. The vulnerability is triggered only when two conditions are met simultaneously: the application uses OpenSSL for DTLS (not regular TLS), and writing a handshake message is paused midway at the moment the retransmission timer fires. Deployments that work exclusively with TLS over TCP are not affected. OpenSSL does not limit the vulnerability to either clients or servers — the fix has been tested in both roles.

The highest risk is for systems that actively use DTLS: WebRTC servers, VoIP infrastructure, UDP-based VPN solutions and IoT devices with DTLS channels.

Affected versions and fixes

According to CNA data, the vulnerability affects the following OpenSSL versions:

  • OpenSSL 4.0.0 – 4.0.2 → fixed in 4.0.3
  • OpenSSL 3.6.0 – 3.6.4 → fixed in 3.6.5
  • OpenSSL 3.5.0 – 3.5.8 → fixed in 3.5.9
  • OpenSSL 3.4.0 – 3.4.7 → fixed in 3.4.8
  • OpenSSL 3.0.0 – 3.0.22 → fixed in 3.0.23 (paid support only)
  • OpenSSL 1.1.1 up to 1.1.1zj → fixed in 1.1.1zj (paid support only)
  • OpenSSL 1.0.2 up to 1.0.2zs → fixed in 1.0.2zs (paid support only)

The 3.0 branch stopped receiving public security updates on 7 September. Version 3.0.23 became the first update in this branch that is not publicly available. For those who build OpenSSL 3.0 themselves or ship it in their products, OpenSSL recommends migrating to a newer branch (4.0 or the 3.5 LTS release) or purchasing a paid support contract.

Linux distributions released updates promptly. According to the original report, Ubuntu published fixes on 29 September:

  • Ubuntu 26.04 LTS: libssl3t64 3.5.5-1ubuntu3.6
  • Ubuntu 24.04 LTS: libssl3t64 3.0.13-0ubuntu3.16
  • Ubuntu 22.04 LTS: libssl3 3.0.2-0ubuntu1.30

Debian fixed the vulnerability in Debian 13 with the openssl package version 3.5.7-1~deb13u3 (DSA-6531-1). As of 07:36 UTC on 30 September, the Debian security tracker was still marking Debian 12 as vulnerable.

Other vulnerabilities in this release

In addition to CVE-2026-84782, the 29 September releases fix 13 more vulnerabilities. Two of them deserve special attention:

CVE-2026-84783 is a use-after-free vulnerability that affects only OpenSSL 4.0. A remote, unauthenticated party can cause a crash of a multithreaded TLS client or a multithreaded TLS server that requests client certificates if several connections simultaneously build the first certificate chains to the same trusted CA. It is worth noting the discrepancy in assessments: the OpenSSL project rates it as Moderate, while CISA ADP assigns CVSS 3.1 7.5 (High).

CVE-2026-75806 is a low-severity vulnerability in DTLS 1.2, according to the OpenSSL release description. Anyone who can send a datagram to an established DTLS 1.2 connection using an AEAD cipher suite can tear it down with a single datagram that is too short, without knowing the keys. The remaining 11 vulnerabilities are also rated as Low and include 5 bugs in QUIC code and 3 timing side-channel vulnerabilities in ECDSA and SM2 code.

Recommendations

  • Update OpenSSL to versions 4.0.3, 3.6.5, 3.5.9 or 3.4.8, depending on the branch you use. The OpenSSL security policy recommends installing updates rated High as soon as possible.
  • Ubuntu users: install the updated libssl packages and reboot — according to Ubuntu, this is required for the changes to take full effect.
  • Debian 12 users: monitor the appearance of a fix in the security tracker.
  • OpenSSL 3.0 users: plan a migration to a supported branch (3.5 LTS or 4.0), since public updates for 3.0 have ended.
  • Audit DTLS usage in your infrastructure — if OpenSSL is used exclusively for TLS over TCP, this particular vulnerability does not affect you.

OpenSSL does not offer workarounds for those who cannot update. The vulnerability was discovered by Laurent Gaffie of Secorizon on 17 August, and the fix was developed by Ryan Hooper — the commit is available on GitHub. Despite the lack of confirmed exploitation, the combination of memory disclosure and the possibility of remote denial of service over a network vector without authentication makes prompt updating a priority task for everyone using DTLS based on OpenSSL.


CyberSecureFox Editorial Team

The CyberSecureFox Editorial Team covers cybersecurity news, vulnerabilities, malware campaigns, ransomware activity, AI security, cloud security, and vendor security advisories. Articles are prepared using official advisories, CVE/NVD data, CISA alerts, vendor publications, and public research reports. Content is reviewed before publication and updated when new information becomes available.

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.