[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fjfLxy9XsVrA3kxhBY74-3UnhrZpTwRORga8SOcNWcPs":3},{"article":4,"iocs":41},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":28,"category":29,"article_tags":33},"80249439-d700-46c9-856b-abc1629c28ac","OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted","openssl-fixes-high-severity-dtls-flaw-that-can-leak-heap-memory-unencrypted-1b25f2","A High-severity OpenSSL flaw can leak heap memory to the other side of a DTLS connection or crash the program, OpenSSL said on September 29 as it released fixes. DTLS, the TLS variant used for UDP traffic, resends a handshake message if no reply arrives before the timer expires. The leak or crash can happen when such a resend starts while a larger handshake message is stuck part-way","OpenSSL has released fixes for a high-severity vulnerability (CVE-2026-84782) in its Datagram Transport Layer Security (DTLS) implementation. The flaw can lead to unencrypted heap memory leaks or program crashes by exploiting how DTLS resends handshake messages. While OpenSSL rates the issue as High, CISA assigned it a CVSS score of 8.2, noting a high impact on availability.","OpenSSL fixes high-severity DTLS flaw allowing heap memory leaks or crashes.","OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted Swati KhandelwalSep 30, 2026Vulnerability \u002F Network Security A High-severity OpenSSL flaw can leak heap memory to the other side of a DTLS connection or crash the program, OpenSSL said on September 29 as it released fixes. DTLS, the TLS variant used for UDP traffic, resends a handshake message if no reply arrives before the timer expires. The leak or crash can happen when such a resend starts while a larger handshake message is stuck part-way through being sent. The flaw, tracked as CVE-2026-84782, is fixed in OpenSSL 4.0.3, 3.6.5, 3.5.9 and 3.4.8. Fixed versions for the older 3.0, 1.1.1 and 1.0.2 branches go only to customers who pay for OpenSSL's premium support. OpenSSL 3.0 stopped getting public security fixes on September 7. OpenSSL has not said whether an attacker can cause a resend while a message is stuck, nor has it reported any attacks exploiting the flaw. DTLS is used, for example, to protect WebRTC data channels and to set up encryption keys for internet calls. Software is exposed to this flaw only if it uses OpenSSL for DTLS. DTLS splits a large handshake message into fragments that each fit in one UDP datagram. If the connection cannot accept more data for the moment, sending can pause part-way through a message and continue later. While sending is paused, the resend timer can still fire and send an earlier message again. Before the fix, the resend used the paused message's position in the buffer instead of going back to the start of the message being resent. The resent message went out with the wrong label. Its body was leftover bytes from the larger message, and reading it could overrun the buffer. The wrongly labeled message can carry heap memory to the other side as unencrypted handshake data, according to OpenSSL. If the read reaches unmapped memory, the program crashes. OpenSSL does not limit the flaw to DTLS clients or servers, and its fix was tested in both roles. Laurent Gaffie of Secorizon reported the flaw on August 17, and Ryan Hooper developed the fix. OpenSSL rates the flaw High, one level below Critical in its severity scale. The project's security policy advises installing updates with High fixes as soon as possible. CISA gave the flaw a CVSS score of 8.2 out of 10 on September 29, rating its impact on confidentiality Low and on availability High. CISA's record listed exploitation as \"none\" at that time. OpenSSL does not use CVSS to set its severity ratings and says scores from outside parties can differ greatly from them. Ubuntu's security notice says an attacker could possibly use the flaw to cause \"incorrect handshake behavior or a denial of service.\" It does not mention leaked memory. Which Versions Fix the Flaw The flaw affects OpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1, and 1.0.2, in every release before the fixed version shown below. Branch Fixed version Who can get it Support status 4.0 4.0.3 Public download Supported until May 14, 2027 3.6 3.6.5 Public download Supported until November 1, 2026 3.5 3.5.9 Public download Long-term support release, supported until April 8, 2030 3.4 3.4.8 Public download Supported until October 22, 2026 3.0 3.0.23 Premium support customers only Public support ended September 7, 2026 1.1.1 1.1.1zj Premium support customers only No public support 1.0.2 1.0.2zs Premium support customers only No public support 3.1, 3.2, 3.3 None listed Not applicable No public support. OpenSSL did not check whether these branches are affected. OpenSSL lists no workaround for users who cannot update yet. Ubuntu fixed the flaw on September 29 in its own packages, which keep older OpenSSL version numbers: Ubuntu 26.04 LTS: libssl3t64 3.5.5-1ubuntu3.6 Ubuntu 24.04 LTS: libssl3t64 3.0.13-0ubuntu3.16 Ubuntu 22.04 LTS: libssl3 3.0.2-0ubuntu1.30 Ubuntu users need to reboot after the update for all the changes to take effect. Debian fixed the flaw in Debian 13 with version 3.5.7-1~deb13u3 of its openssl package, released as DSA-6531-1. Its security tracker still listed Debian 12 as vulnerable as of 07:36 UTC on September 30. What OpenSSL 3.0 Users Can Do The last public 3.0 release was 3.0.22, on August 25. Version 3.0.23 is the first 3.0 security release that OpenSSL has not made public. It fixes 6 of the 14 flaws disclosed on September 29, including CVE-2026-84782. For Ubuntu 22.04 and 24.04, which use OpenSSL 3.0, the fix is already available in the packages listed above. Anyone who builds OpenSSL 3.0 or ships a copy inside their own software has no public fix from OpenSSL. OpenSSL recommends upgrading to a newer branch, such as 4.0 or the long-term support release 3.5. The other option is a paid support contract, which gives ongoing access to security fixes for releases past their public end date. The September 29 releases fix 13 other flaws. The most serious of them, CVE-2026-84783, is rated Moderate and affects only OpenSSL 4.0. A remote, unauthenticated peer could use it to crash a multi-threaded TLS client, or a multi-threaded TLS server that asks for client certificates. That can happen only if several connections build their first certificate chains to the same trusted CA certificate at the same time. Another DTLS flaw, CVE-2026-75806, is rated Low. It affects established DTLS 1.2 connections that use an AEAD cipher suite. Anyone who can send a datagram to such a connection can end it with a single too-short datagram without knowing any keys. The other 11 flaws are also rated Low and include 5 in OpenSSL's QUIC code and 3 timing side-channels in ECDSA and SM2 code. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  cryptography, network security, Open Source Security, Vulnerability ⚡ Top Stories This Week Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access Beyond ISO 27001: Building a Risk Program That Can Keep Up With AI Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignore ⭐ Featured Resources Validation Summit ’26: See How Pen Testing, Exposure Validation and BAS Work Together Red Teams: Learn ","https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Fopenssl-fixes-high-severity-dtls-flaw.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEj0Po53IuyRAhsYzbs5KKPp_UBpklONBiOzoLWgXrklvrgDn5xnpjuRjU8UYoyLuImSmiPtOHQK3ExgQk5zhxlqsAcUmTLRFowkQXzan2RD955Gw-sumsvmwzLBTViUBRhyphenhyphenHCnETV23Qbt01RwaovTe1ogMeMYDSGxmF5n84NKZOB3EiWz6VAHUlfDm5YE\u002Fs1600\u002Fopenssl-memory.jpg","2026-09-30T08:09:28+00:00","2026-09-30T10:00:15.011403+00:00",8,[18,21,24,26],{"name":19,"type":20},"OpenSSL","product",{"name":22,"type":23},"DTLS","technology",{"name":25,"type":23},"UDP",{"name":27,"type":23},"WebRTC","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":28,"icon":30,"name":31,"slug":32},null,"Vulnerabilities","vulnerabilities",[34,36],{"category":35},{"id":28,"icon":30,"name":31,"slug":32},{"category":37},{"id":38,"icon":30,"name":39,"slug":40},"ade75414-7914-4e23-a450-48b64546ee70","Open Source","open-source",[42],{"type":43,"value":44,"context":45},"cve","CVE-2026-84782","High-severity DTLS flaw in OpenSSL"]