OpenSSL announced on September 29 that it has fixed a high-severity flaw in its DTLS implementation, tracked as CVE-2026-84782. This vulnerability could lead to heap memory leakage to the other side of a DTLS connection or cause the program to crash. DTLS is a variant of TLS specifically designed for UDP traffic.
The flaw occurs when a DTLS handshake message resend is initiated while a larger handshake message is partially sent. DTLS fragments large handshake messages into smaller UDP datagrams. If sending pauses due to connection limitations, the resend timer can still trigger an earlier message to be sent again. Before the fix, the resend operation incorrectly used the paused message's buffer position, leading to the resent message carrying leftover bytes from the larger, partially sent message. This could expose heap memory unencrypted or cause a crash if unmapped memory was accessed.
The vulnerability has been addressed in OpenSSL versions 4.0.3, 3.6.5, 3.5.9, and 3.4.8. For older branches, specifically 3.0, 1.1.1, and 1.0.2, fixes are only available to customers with premium support. OpenSSL 3.0 ceased receiving public security fixes on September 7. The project advises installing updates for high-severity fixes as soon as possible.
Software is susceptible to this flaw only if it utilizes OpenSSL for DTLS. Examples of DTLS usage include protecting WebRTC data channels and setting up encryption keys for internet calls. OpenSSL has not confirmed whether an attacker can reliably trigger a resend while a message is stuck, nor have any active exploits been reported. The flaw was reported by Laurent Gaffie of Secorizon on August 17, with Ryan Hooper developing the fix. CISA assigned the flaw a CVSS score of 8.2, rating its confidentiality impact as Low and availability impact as High.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
OpenSSL released fixes for a high-severity DTLS flaw, CVE-2026-84782, that can leak heap memory or crash programs during handshake message resends. The vulnerability affects software using OpenSSL for DTLS and is patched in versions 4.0.3, 3.6.5, 3.5.9, and 3.4.8, with premium support required for older branches.