OpenSSL Patches High-Severity DTLS Vulnerability Exposing Heap Memory
On September 29, 2026, the OpenSSL Project released security updates addressing CVE-2026-84782, a high-severity vulnerability in its Datagram Transport Layer Security (DTLS) handshake logic. The flaw, classified as an out-of-bounds read (CWE-125), could expose adjacent heap memory as plaintext during retransmissions or crash affected processes, leading to a denial-of-service (DoS) condition.
Vulnerability Details
The issue arises when OpenSSL suspends a DTLS handshake message write due to transport limitations (returning WANT_WRITE). If a retransmission timer triggers while the write remains paused, vulnerable versions fail to reset the read offset, causing the retransmission to begin at a stale position. This can result in:
- Memory leaks: Leftover bytes from unrelated messages may be sent as plaintext handshake data, potentially exposing sensitive process memory.
- Process crashes: If the out-of-bounds read hits unmapped memory, the process terminates, enabling DoS attacks.
Additionally, completing a retransmission while another handshake write is suspended corrupts shared state tracking, leading to inconsistent operations and potential aborts in debugging builds.
Affected Versions & Fixes
The vulnerability impacts all OpenSSL branches, including:
- 4.0.x (before 4.0.3)
- 3.6.x (before 3.6.5)
- 3.5.x (before 3.5.9)
- 3.4.x (before 3.4.8)
- 3.0.x (before 3.0.23)
- 1.1.1 (before 1.1.1zj)
- 1.0.2 (before 1.0.2zs)
Patches are available in OpenSSL 4.0.3, 3.6.5, 3.5.9, and 3.4.8 for maintained branches. Fixes for 3.0.x, 1.1.1, and 1.0.2 are limited to premium support customers. The OpenSSL FIPS module is not affected, as the flaw resides outside its boundary.
Discovery & Mitigation
The vulnerability was reported by Laurent Gaffie of Secorizon on August 17, 2026, and patched by Ryan Hooper. The fix resets the retransmission read position before resending messages and defers retransmissions while handshake writes are suspended.
Broader Impact
OpenSSL 4.0.3 also addresses 13 additional vulnerabilities in X.509 processing, QUIC, CMP, DTLS, SM2, and elliptic-curve operations, reinforcing the urgency of upgrading. Administrators should audit appliances, embedded systems, VPNs, and applications using OpenSSL DTLS, as bundled copies may not be detected by system package managers.
The flaw underscores the risks of state-management errors in cryptographic protocols, particularly in unreliable transport environments like DTLS.
Source: https://cybersecuritynews.com/openssl-leak-server-memory/
OpenSSL Project TPRM report: https://www.rankiteo.com/company/openssl-foundation
"id": "ope1790742421",
"linkid": "openssl-foundation",
"type": "Vulnerability",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Users of OpenSSL DTLS in '
'versions 4.0.x (before 4.0.3), '
'3.6.x (before 3.6.5), 3.5.x '
'(before 3.5.9), 3.4.x (before '
'3.4.8), 3.0.x (before 3.0.23), '
'1.1.1 (before 1.1.1zj), and '
'1.0.2 (before 1.0.2zs)',
'industry': 'Cybersecurity/Software',
'name': 'OpenSSL Project',
'type': 'Software Provider'}],
'attack_vector': 'Network',
'customer_advisories': 'Users of OpenSSL DTLS should apply patches '
'immediately to mitigate memory exposure and DoS '
'risks.',
'data_breach': {'sensitivity_of_data': 'High (if sensitive process memory is '
'exposed)',
'type_of_data_compromised': 'Heap memory (potentially '
'sensitive process data)'},
'date_detected': '2026-08-17',
'date_publicly_disclosed': '2026-09-29',
'date_resolved': '2026-09-29',
'description': 'On September 29, 2026, the OpenSSL Project released security '
'updates addressing CVE-2026-84782, a high-severity '
'vulnerability in its Datagram Transport Layer Security (DTLS) '
'handshake logic. The flaw, classified as an out-of-bounds '
'read (CWE-125), could expose adjacent heap memory as '
'plaintext during retransmissions or crash affected processes, '
'leading to a denial-of-service (DoS) condition. The issue '
'arises when OpenSSL suspends a DTLS handshake message write '
'due to transport limitations (returning WANT_WRITE). If a '
'retransmission timer triggers while the write remains paused, '
'vulnerable versions fail to reset the read offset, causing '
'the retransmission to begin at a stale position. This can '
'result in memory leaks or process crashes.',
'impact': {'brand_reputation_impact': 'Potential reputational damage due to '
'security vulnerability',
'data_compromised': 'Heap memory exposure (potentially sensitive '
'process memory)',
'downtime': 'Potential process crashes leading to '
'denial-of-service (DoS)',
'operational_impact': 'Potential service disruptions due to DoS or '
'memory corruption',
'systems_affected': 'Systems using OpenSSL DTLS (appliances, '
'embedded systems, VPNs, applications)'},
'investigation_status': 'Resolved',
'lessons_learned': 'The flaw underscores the risks of state-management errors '
'in cryptographic protocols, particularly in unreliable '
'transport environments like DTLS.',
'post_incident_analysis': {'corrective_actions': 'Reset retransmission read '
'position before resending '
'messages; defer '
'retransmissions while '
'handshake writes are '
'suspended.',
'root_causes': 'State-management error in DTLS '
'handshake logic (failure to reset '
'read offset during '
'retransmissions)'},
'recommendations': 'Administrators should audit appliances, embedded systems, '
'VPNs, and applications using OpenSSL DTLS for bundled '
'copies and apply patches immediately. Maintain awareness '
'of cryptographic protocol vulnerabilities in unreliable '
'transport environments.',
'references': [{'date_accessed': '2026-09-29', 'source': 'OpenSSL Project'},
{'date_accessed': '2026-09-29',
'source': 'Secorizon (Laurent Gaffie)'}],
'response': {'communication_strategy': 'Public disclosure and advisory by '
'OpenSSL Project',
'containment_measures': 'Patches released for affected OpenSSL '
'versions',
'remediation_measures': 'Upgrade to OpenSSL 4.0.3, 3.6.5, 3.5.9, '
'3.4.8, or later; audit systems for '
'bundled OpenSSL copies'},
'stakeholder_advisories': 'Upgrade to patched OpenSSL versions; audit systems '
'for vulnerable DTLS implementations.',
'title': 'OpenSSL Patches High-Severity DTLS Vulnerability Exposing Heap '
'Memory (CVE-2026-84782)',
'type': 'Vulnerability Exploitation',
'vulnerability_exploited': 'CVE-2026-84782 (Out-of-bounds read in DTLS '
'handshake logic)'}