HomeSecurityOpenSSL: Critical DTLS vulnerability leaks heap memory

OpenSSL: Critical DTLS vulnerability leaks heap memory

A serious vulnerability in OpenSSL allows a heap memory leak to the other side of a DTLS connection or can cause the program to crash. OpenSSL announced the release of patches on September 29, 2026 , urging all users to update as soon as possible. The issue affects widely used versions of the library and puts systems that rely on DTLS for encrypted communications at risk

See also: Mozilla Firefox: Fixes “Heap Buffer Overflow” vulnerability

OpenSSL DTLS vulnerability CVE-2026-84782 heap memory leak

The vulnerability is tracked as CVE-2026-84782 and is rated High on the OpenSSL severity scale — one notch below Critical. CISA has assigned it a CVSS score of 8.2 out of 10 , rating the confidentiality impact as Low and the availability impact as High. No attacks have been reported to date that exploit the vulnerability, but its nature makes it imperative to be notified immediately.

DTLS ( Datagram Transport Layer Security ) is the variant of TLS used for UDP traffic. It is widely implemented to protect WebRTC data channels , to generate encryption keys in Internet calls (VoIP) and in other real-time applications. The software is exposed to the vulnerability only if it uses OpenSSL for DTLS communications.

How the CVE-2026-84782 vulnerability in OpenSSL DTLS works

To understand the vulnerability, we need to look at how DTLS. The protocol breaks a large handshake into fragments, each of which fits into a UDP datagram. If the connection cannot accept more data at that time, the transmission can be stopped in the middle of a message and resumed later. DTLS resends a handshake message if no response is received before the timer expires.

The issue occurs when a retransmission is initiated while a larger message is paused in the middle of being sent. Before the fix, the retransmission used the buffer position of the paused message, instead of returning to the beginning of the message being retransmitted. Result: the retransmitted message would be output with the wrong label, while its body contained leftover bytes from the larger message. Reading these bytes could exceed the buffer limits.

The incorrectly marked message can transfer heap to the other side as unencrypted handshake data. If the read reaches unmapped memory, the program crashes. OpenSSL does not limit the vulnerability to DTLS clients or servers — the fix was tested in both roles. This means that both client applications and servers that use OpenSSL for DTLS are exposed.

See also: iOS 27 beta 6: What's new, what security fixes and which iPhones support it

OpenSSL: Critical DTLS vulnerability leaks heap memory

Which OpenSSL versions are affected and how to protect yourself

The vulnerability CVE-2026-84782 affects OpenSSL versions 4.0 , 3.6 , 3.5 , 3.4 , 3.0 , 1.1.1 , and 1.0.2 , in each version before the patch. The fix is ​​available in versions 4.0.3 , 3.6.5 , 3.5.9 , and 3.4.8 . For older branches 3.0 , 1.1.1 , and 1.0.2 , the patch is only available to customers who pay for premium OpenSSL support . It is worth noting that the OpenSSL 3.0 branch stopped receiving public security fixes on September 7, 2026 .

The last public release of the 3.0 was 3.0.22, on August 25. Version 3.0.23 is the first security release of the 3.0 that OpenSSL has not released publicly — it fixes 6 of the 14 vulnerabilities disclosed on September 29 , including CVE-2026-84782. This means that anyone building OpenSSL 3.0 or incorporating it into their own software does not have a public fix from OpenSSL.

For Linux distribution users , the situation is more favorable. Ubuntu patched the vulnerability on September 29 in its own packages, which retain older OpenSSL version numbers . Ubuntu users must reboot their systems after the update for all changes to take effect. For Ubuntu 22.04 and 24.04 , which use OpenSSL 3.0 , the fix is ​​already available in the respective packages. Debian patched the vulnerability in Debian 13 with version 3.5.7-1~deb13u3 of the openssl package, released as DSA-6531-1 , while Debian 12 remained vulnerable on September 30 .

OpenSSL does not provide any workaround for users who cannot update immediately. The official recommendation is to upgrade to a newer branch, such as 4.0 or the long-term support branch 3.5 . The other option is to sign up for a paid support contract, which provides continued access to security fixes for versions that have passed their public support end date.

Discovery, fix, and wider impact of the OpenSSL DTLS bug

The vulnerability was discovered and reported by Laurent Gaffie of Secorizon on August 17, 2026. The fix was developed by Ryan Hooper . OpenSSL 's security policy recommends installing updates with High level fixes as soon as possible. It is worth noting that OpenSSL does not use the CVSS system for its own severity ratings and notes that third-party scores can vary significantly. CISA assessed the availability impact as High, reflecting the denial of service risk posed by the vulnerability.

The importance of this vulnerability should not be underestimated. OpenSSL is the encryption backbone of countless applications and services worldwide. A heap memory leak via unencrypted handshake data could expose sensitive information held in memory — keys, credentials, or other critical data. At the same time, the ability to cause a program crash via denial of service could impact the availability of DTLS -based services . The September 29 releases fix a total of 14 vulnerabilities , making the update even more urgent, according to The Hacker News.

See also: Knot Resolver: RCE via DoQ heap overflow (CVE-2026-66374) – what admins should do

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Concrete CMS security patch on web server

For organizations and system administrators using OpenSSL , immediate action is necessary. The first step is to identify all systems using OpenSSL for DTLS communications. The second is to upgrade to the patched versions 4.0.3 , 3.6.5 , 3.5.9 , or 3.4.8 depending on the branch being used. For users of Linux distributions such as Ubuntu and Debian , applying the available package updates is the most immediate solution. Those using the 3.0 branch without a support contract should plan to migrate to a newer branch immediately, as there is no public fix for them.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS