OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted

A high-severity OpenSSL vulnerability could lead to heap memory disclosure on the other side of a DTLS connection or cause a program crash, OpenSSL said September 29 as it rolled out fixes.

DTLS (the TLS variant used for UDP traffic) re-sends a handshake message if no response is received before the timeout, and the leak or crash could occur during such a resend if a larger handshake message was paused in transmission.

The vulnerability, CVE-2026-84782, is fixed in OpenSSL 4.0.3, 3.6.5, 3.5.9 and 3.4.8. Fixes for the older 3.0, 1.1.1 and 1.0.2 branches are available only to customers with an active subscription for premium support from OpenSSL. OpenSSL 3.0 stopped receiving public security fixes on September 7.

OpenSSL has not said whether an attacker could cause such a resend to occur while a message was paused, nor has it reported any attacks using the vulnerability.

DTLS is used, for example, to secure WebRTC data channels and to establish encryption keys for internet calls. Software is vulnerable only if it uses OpenSSL to implement DTLS.

DTLS breaks up a large handshake message into smaller pieces, each of which fits in a UDP datagram. If the connection cannot accept more data for the moment, sending can be paused part-way through a message and resumed later. While sending is paused, the resend timer can still go off and send an earlier message again read more about OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *