securityonline.info 29 Sept 2026, 19:20 UTC

OpenSSL Fixes 14 Flaws as DTLS Bug Risks Memory Leaks

OpenSSL Fixes 14 Flaws as DTLS Bug Risks Memory Leaks
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Available

OPENSSL has released a security advisory fixing 14 vulnerabilities across its recent trunks, including one high-severity issue that can leak heap memory during a DTLS handshake and potentially crash the process. The advisory, dated 29 September 2026, identifies four High, three Medium, three Low, and four unrated CVEs.

The most significant entry is CVE-2026-84782, rated 8.2, which can disclose heap memory to a peer or cause a crash, and CVE-2026-84783, rated 7.5, a cache-use-after-free in X.509 handling that can crash a multi-threaded TLS client or a server handling client certificates. None of the issues are reported as exploited in the wild at this time.

OpenSSL notes that CVE-2026-84782 affects OpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1, and 1.0.2, while CVE-2026-84783 affects only the 4.0 line. The fixes are released in OpenSSL versions 4.0.3, 3.6.5, 3.5.9, and 3.4.8, with premium users on older branches advised to upgrade to 3.0.23, 1.1.1zj, or 1.0.2zs. The bulk of the remaining issues are low-severity, many tied to the QUIC stack or timing side channels, and some involve crafted certificates or a CMP client crash.

Organisations should prioritise DTLS and QUIC services when applying patches. The advisory confirms that the FIPS module is unaffected and currently notes no in-the-wild exploitation for these fixes.

View full article

Article by CyberSIXT