← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory or Crash Programs

🔄 Updated 2d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • High-severity DTLS flaw CVE-2026-84782 fixed.
  • Can leak heap memory or crash programs.
  • Fixed in OpenSSL 4.0.3, 3.6.5, 3.5.9, 3.4.8.
  • Affects software using OpenSSL for DTLS.

High-Severity DTLS Flaw Discovered

OpenSSL announced on September 29 that it has fixed a high-severity flaw in its DTLS implementation, tracked as CVE-2026-84782. This vulnerability could lead to heap memory leakage to the other side of a DTLS connection or cause the program to crash. DTLS is a variant of TLS specifically designed for UDP traffic.

Technical Details of the Vulnerability

The flaw occurs when a DTLS handshake message resend is initiated while a larger handshake message is partially sent. DTLS fragments large handshake messages into smaller UDP datagrams. If sending pauses due to connection limitations, the resend timer can still trigger an earlier message to be sent again. Before the fix, the resend operation incorrectly used the paused message's buffer position, leading to the resent message carrying leftover bytes from the larger, partially sent message. This could expose heap memory unencrypted or cause a crash if unmapped memory was accessed.

Affected Versions and Fixes

The vulnerability has been addressed in OpenSSL versions 4.0.3, 3.6.5, 3.5.9, and 3.4.8. For older branches, specifically 3.0, 1.1.1, and 1.0.2, fixes are only available to customers with premium support. OpenSSL 3.0 ceased receiving public security fixes on September 7. The project advises installing updates for high-severity fixes as soon as possible.

Impact and Exploitation Status

Software is susceptible to this flaw only if it utilizes OpenSSL for DTLS. Examples of DTLS usage include protecting WebRTC data channels and setting up encryption keys for internet calls. OpenSSL has not confirmed whether an attacker can reliably trigger a resend while a message is stuck, nor have any active exploits been reported. The flaw was reported by Laurent Gaffie of Secorizon on August 17, with Ryan Hooper developing the fix. CISA assigned the flaw a CVSS score of 8.2, rating its confidentiality impact as Low and availability impact as High.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

OpenSSL released fixes for a high-severity DTLS flaw, CVE-2026-84782, that can leak heap memory or crash programs during handshake message resends. The vulnerability affects software using OpenSSL for DTLS and is patched in versions 4.0.3, 3.6.5, 3.5.9, and 3.4.8, with premium support required for older branches.