OPENSSL has disclosed a high-severity vulnerability in its DTLS implementation that can cause a heap memory leak to the peer or crash the vulnerable process. Tracked as CVE-2026-84782, the flaw occurs when a DTLS handshake message is being resent while a larger handshake fragment remains in flight; the resend could misuse the buffered data, potentially sending leftover bytes as an unencrypted payload and leaking memory across the connection or triggering a crash.
OpenSSL states the issue can affect both DTLS clients and servers, and the problem arises during the pause-and-resend window when fragmentation and buffering interact with the retransmission timer.
The advisory specifies fixed OpenSSL versions as follows: 4.0.3, 3.6.5, 3.5.9 and 3.4.8. Earlier branches (3.0, 1.1.1 and 1.0.2) have fixes available only to premium-support customers. OpenSSL notes it has not confirmed active exploitation at this time. CISA assigns a CVSS score of 8.2 (high) with impact on confidentiality listed as Low and availability as High; Ubuntu’s notice indicates possible incorrect handshake behaviour or denial of service, with no explicit memory leak mentioned.
The fix has been tested in both DTLS client and server roles, and users should upgrade to a fixed branch where possible, or rely on vendor-supplied packages (with reboot required in some Ubuntu packages) to mitigate the risk.