A High-severity OpenSSL flaw can leak heap memory to the other side of a DTLS connection or crash the program, OpenSSL said on September 29 as it released fixes.

DTLS, the TLS variant used for UDP traffic, resends a handshake message if no reply arrives before the timer expires. The leak or crash can happen when such a resend starts while a larger handshake message is stuck part-way through being sent.

The flaw, tracked as CVE-2026-84782, is fixed in OpenSSL 4.0.3, 3.6.5, 3.5.9 and 3.4.8. Fixed versions for the older 3.0, 1.1.1 and 1.0.2 branches go only to customers who pay for OpenSSL’s premium support. OpenSSL 3.0 stopped getting public security fixes on September 7.

OpenSSL has not said whether an attacker can cause a resend while a message is stuck, nor has it reported any attacks exploiting the flaw.

DTLS is used, for example, to protect WebRTC data channels and to set up encryption keys for internet calls. Software is exposed to this flaw only if it uses OpenSSL for DTLS.

DTLS splits a large handshake message into fragments that each fit in one UDP datagram. If the connection cannot accept more data for the moment, sending can pause part-way through a message and continue later. While sending is paused, the resend timer can still fire and send an earlier message again.

Cybersecurity

Before the fix, the resend used the paused message’s position in the buffer instead of going back to the start of the message being resent. The resent message went out with the wrong label. Its body was leftover bytes from the larger message, and reading it could overrun the buffer.

The wrongly labeled message can carry heap memory to the other side as unencrypted handshake data, according to OpenSSL. If the read reaches unmapped memory, the program crashes.

OpenSSL does not limit the flaw to DTLS clients or servers, and its fix was tested in both roles.

Laurent Gaffie of Secorizon reported the flaw on August 17, and Ryan Hooper developed the fix.

OpenSSL rates the flaw High, one level below Critical in its severity scale. The project’s security policy advises installing updates with High fixes as soon as possible.

CISA gave the flaw a CVSS score of 8.2 out of 10 on September 29, rating its impact on confidentiality Low and on availability High. CISA’s record listed exploitation as «none» at that time. OpenSSL does not use CVSS to set its severity ratings and says scores from outside parties can differ greatly from them.

Ubuntu’s security notice says an attacker could possibly use the flaw to cause «incorrect handshake behavior or a denial of service.» It does not mention leaked memory.

Which Versions Fix the Flaw

The flaw affects OpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1, and 1.0.2, in every release before the fixed version shown below.

Branch Fixed version Who can get it Support status
4.0 4.0.3 Public download Supported until May 14, 2027
3.6 3.6.5 Public download Supported until November 1, 2026
3.5 3.5.9 Public download Long-term support release, supported until April 8, 2030
3.4 3.4.8 Public download Supported until October 22, 2026
3.0 3.0.23 Premium support customers only Public support ended September 7, 2026
1.1.1 1.1.1zj Premium support customers only No public support
1.0.2 1.0.2zs Premium support customers only No public support
3.1, 3.2, 3.3 None listed Not applicable No public support. OpenSSL did not check whether these branches are affected.

OpenSSL lists no workaround for users who cannot update yet. Ubuntu fixed the flaw on September 29 in its own packages, which keep older OpenSSL version numbers:

  • Ubuntu 26.04 LTS: libssl3t64 3.5.5-1ubuntu3.6
  • Ubuntu 24.04 LTS: libssl3t64 3.0.13-0ubuntu3.16
  • Ubuntu 22.04 LTS: libssl3 3.0.2-0ubuntu1.30

Ubuntu users need to reboot after the update for all the changes to take effect.

Debian fixed the flaw in Debian 13 with version 3.5.7-1~deb13u3 of its openssl package, released as DSA-6531-1. Its security tracker still listed Debian 12 as vulnerable as of 07:36 UTC on September 30.

What OpenSSL 3.0 Users Can Do

The last public 3.0 release was 3.0.22, on August 25. Version 3.0.23 is the first 3.0 security release that OpenSSL has not made public. It fixes 6 of the 14 flaws disclosed on September 29, including CVE-2026-84782.

For Ubuntu 22.04 and 24.04, which use OpenSSL 3.0, the fix is already available in the packages listed above. Anyone who builds OpenSSL 3.0 or ships a copy inside their own software has no public fix from OpenSSL.

Cybersecurity

OpenSSL recommends upgrading to a newer branch, such as 4.0 or the long-term support release 3.5. The other option is a paid support contract, which gives ongoing access to security fixes for releases past their public end date.

The September 29 releases fix 13 other flaws. The most serious of them, CVE-2026-84783, is rated Moderate and affects only OpenSSL 4.0.

A remote, unauthenticated peer could use it to crash a multi-threaded TLS client, or a multi-threaded TLS server that asks for client certificates. That can happen only if several connections build their first certificate chains to the same trusted CA certificate at the same time.

Another DTLS flaw, CVE-2026-75806, is rated Low. It affects established DTLS 1.2 connections that use an AEAD cipher suite. Anyone who can send a datagram to such a connection can end it with a single too-short datagram without knowing any keys.

The other 11 flaws are also rated Low and include 5 in OpenSSL’s QUIC code and 3 timing side-channels in ECDSA and SM2 code.