thehackernews.com 30 Sept 2026, 08:09 UTC

OpenSSL DTLS Flaw Can Leak Memory or Crash Clients and Servers

CyberSIXT Evidence Panel
CVE Intel
CISA KEV Not in KEV
Patch Patch Available

OPENSSL has disclosed a high-severity vulnerability in its DTLS implementation that can cause a heap memory leak to the peer or crash the vulnerable process. Tracked as CVE-2026-84782, the flaw occurs when a DTLS handshake message is being resent while a larger handshake fragment remains in flight; the resend could misuse the buffered data, potentially sending leftover bytes as an unencrypted payload and leaking memory across the connection or triggering a crash.

OpenSSL states the issue can affect both DTLS clients and servers, and the problem arises during the pause-and-resend window when fragmentation and buffering interact with the retransmission timer.

The advisory specifies fixed OpenSSL versions as follows: 4.0.3, 3.6.5, 3.5.9 and 3.4.8. Earlier branches (3.0, 1.1.1 and 1.0.2) have fixes available only to premium-support customers. OpenSSL notes it has not confirmed active exploitation at this time. CISA assigns a CVSS score of 8.2 (high) with impact on confidentiality listed as Low and availability as High; Ubuntu’s notice indicates possible incorrect handshake behaviour or denial of service, with no explicit memory leak mentioned.

The fix has been tested in both DTLS client and server roles, and users should upgrade to a fixed branch where possible, or rely on vendor-supplied packages (with reboot required in some Ubuntu packages) to mitigate the risk.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline