Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

OpenSSL Addresses High-Severity DTLS Flaw That Can Leaked Heap Memory Unencrypted




OpenSSL has released fixes for a high-severity DTLS flaw that can leak heap memory unencrypted. The flaw, tracked as CVE-2026-84782, has been assigned a CVSS score of 8.2, indicating its impact on confidentiality is Low and on availability is High. The fixes are available in OpenSSL 4.0.3, 3.6.5, 3.5.9, and 3.4.8. Users are advised to upgrade to a newer branch or a paid support contract to receive ongoing access to security fixes.

  • OpenSSL released fixes for a high-severity DTLS flaw that can leak heap memory unencrypted.
  • The flaw, CVE-2026-84782, can cause a leak or crash of the program if a resend of a handshake message is sent while a larger message is stuck.
  • The vulnerability is significant, affecting software that uses OpenSSL for DTLS, which is used for WebRTC data channels and internet calls.
  • The flaw is caused by a resend of a handshake message starting while a larger message is stuck, leading to a buffer overrun and potential crash.
  • The vulnerability has been assigned a CVSS score of 8.2, indicating its impact on availability is High.
  • Fixes are available in OpenSSL 4.0.3, 3.6.5, 3.5.9, and 3.4.8, but may require paid support for older branches.
  • Users are advised to upgrade to a newer branch or pay for OpenSSL's premium support to receive ongoing security fixes.



  • The cyber security landscape has witnessed a significant development recently, with OpenSSL addressing a high-severity DTLS flaw that can leak heap memory unencrypted. The announcement was made by OpenSSL on September 29, as it released fixes for the vulnerability. This development has garnered considerable attention, given the potential implications of the flaw on system security.

    The DTLS variant, used for UDP traffic, resends a handshake message if no reply arrives before the timer expires. The flaw, tracked as CVE-2026-84782, is caused by a resend that starts while a larger handshake message is stuck part-way through being sent. This can lead to a leak or crash of the program.

    OpenSSL has not indicated whether an attacker can cause a resend while a message is stuck, nor has it reported any attacks exploiting the flaw. However, the vulnerability is significant, and its impact should not be underestimated. DTLS is used, for instance, to protect WebRTC data channels and to set up encryption keys for internet calls. Software that uses OpenSSL for DTLS is exposed to this flaw.

    The flaw can be attributed to the way OpenSSL handles the resend of a handshake message. When sending is paused, the resend timer can still fire and send an earlier message again. The resent message, in this case, goes out with the wrong label. Its body is comprised of leftover bytes from the larger message, and reading it can overrun the buffer. If the read reaches unmapped memory, the program crashes.

    This vulnerability has been assigned a CVSS score of 8.2, out of 10, by CISA, indicating its impact on confidentiality is Low and on availability is High. It is worth noting that OpenSSL does not use CVSS to set its severity ratings and may differ from external party scores.

    The fixes for the flaw are available in OpenSSL 4.0.3, 3.6.5, 3.5.9, and 3.4.8. However, for older branches, particularly 3.0, 1.1.1, and 1.0.2, the fixes are only available to customers who pay for OpenSSL's premium support.

    Ubuntu, Debian, and other distributions have also released fixes for the vulnerability. Users are advised to upgrade to a newer branch or a paid support contract to receive ongoing access to security fixes.

    In conclusion, the recent OpenSSL release has addressed a high-severity DTLS flaw that can leak heap memory unencrypted. The implications of this flaw are significant, and its impact should not be underestimated. It is imperative that users and organizations take prompt action to update their systems and ensure that they are protected against this vulnerability.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/OpenSSL-Addresses-High-Severity-DTLS-Flaw-That-Can-Leaked-Heap-Memory-Unencrypted-ehn.shtml

  • https://thehackernews.com/2026/09/openssl-fixes-high-severity-dtls-flaw.html

  • https://nvd.nist.gov/vuln/detail/CVE-2026-84782

  • https://www.cvedetails.com/cve/CVE-2026-84782/


  • Published: Wed Sep 30 07:28:29 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us