Full Report
A High-severity OpenSSL flaw can leak heap memory to the other side of a DTLS connection or crash the program, OpenSSL said on September 29 as it released fixes. DTLS, the TLS variant used for UDP traffic, resends a handshake message if no reply arrives before the timer expires. The leak or crash can happen when such a resend starts while a larger handshake message is stuck part-way
Analysis Summary
# Vulnerability: OpenSSL DTLS Heap Memory Leak and DoS
## CVE Details
- **CVE ID:** CVE-2026-84782
- **CVSS Score:** 8.2 (High)
- **CWE:** CWE-125 (Out-of-bounds Read) / CWE-401 (Memory Leak)
## Affected Systems
- **Products:** Software utilizing the OpenSSL library for Datagram Transport Layer Security (DTLS) connections (e.g., WebRTC, VoIP services).
- **Versions:**
- OpenSSL 4.0 (prior to 4.0.3)
- OpenSSL 3.6 (prior to 3.6.5)
- OpenSSL 3.5 (prior to 3.5.9)
- OpenSSL 3.4 (prior to 3.4.8)
- OpenSSL 3.0 (prior to 3.0.23)
- OpenSSL 1.1.1 (prior to 1.1.1zj)
- OpenSSL 1.0.2 (prior to 1.0.2zs)
- **Configurations:** Systems configured to handle DTLS traffic (UDP-based TLS). Both clients and servers are affected.
## Vulnerability Description
The flaw exists in the DTLS handshake implementation. DTLS resends handshake messages if a timeout occurs. If a resend is triggered while a large handshake message is currently paused (partially sent), OpenSSL incorrectly uses the current buffer position of the paused message instead of restarting from the beginning.
This leads to the resent message containing leftover bytes from the heap memory instead of the intended handshake data. This "wrongly labeled" message can leak unencrypted heap memory to the peer. Furthermore, if the read operation attempts to access unmapped memory addresses, the program will crash.
## Exploitation
- **Status:** Not exploited in the wild; no public PoC available (as of report date).
- **Complexity:** Medium (Requires specific timing during a fragmented DTLS handshake).
- **Attack Vector:** Network (Remote).
## Impact
- **Confidentiality:** Low (CISA rating; potential leak of heap memory segments).
- **Integrity:** None reported.
- **Availability:** High (Potential for application crash/Denial of Service).
## Remediation
### Patches
Update to the following versions immediately:
- **OpenSSL 4.0.3**
- **OpenSSL 3.6.5**
- **OpenSSL 3.5.9 (LTS)**
- **OpenSSL 3.4.8**
- **OpenSSL 3.0.23, 1.1.1zj, 1.0.2zs** (Available only for Premium Support customers).
Linux Distribution specific fixes:
- **Ubuntu 26.04 LTS:** libssl3t64 3.5.5-1ubuntu3.6
- **Ubuntu 24.04 LTS:** libssl3t64 3.0.13-0ubuntu3.16
- **Ubuntu 22.04 LTS:** libssl3 3.0.2-0ubuntu1.30
- **Debian 13:** openssl 3.5.7-1~deb13u3
### Workarounds
- No specific workarounds are currently provided by the OpenSSL project. Disabling DTLS or migrating to standard TLS (TCP) may mitigate risk if feasible for the environment.
## Detection
- **Indicators of Compromise:** Unusual DTLS handshake patterns, specifically frequent retransmissions followed by application crashes or malformed handshake packets.
- **Detection methods and tools:** Use network monitoring tools (e.g., Wireshark, Zeek) to inspect DTLS handshake fragments for unexpected data in the message body. Run memory sanitizers on internal applications to detect out-of-bounds reads.
## References
- **OpenSSL Security Advisory:** hxxps://openssl-library[.]org/news/secadv/20260929.txt
- **CISA Vulnrichment:** hxxps://github[.]com/cisagov/vulnrichment/blob/develop/2026/84xxx/CVE-2026-84782.json
- **Ubuntu Security Notice:** hxxps://ubuntu[.]com/security/notices/USN-8847-1
- **Debian Security Tracker:** hxxps://security-tracker[.]debian[.]org/tracker/CVE-2026-84782