OpenSSL Patches High-Risk DTLS Memory Leak Flaw
Immagine generata dall'IA

OpenSSL Patches High-Risk DTLS Memory Leak Flaw

A high-severity OpenSSL bug (CVE-2026-84782) can leak heap memory over DTLS or crash apps. Fixes are out for supported versions and major distros.

OpenSSL has patched a high-severity vulnerability in its DTLS (Datagram Transport Layer Security) implementation that can silently leak heap memory to a remote peer or crash the application entirely. The flaw, tracked as CVE-2026-84782, was disclosed on September 29 along with 13 other security fixes for the widely used cryptographic library.

DTLS is the variant of TLS (Transport Layer Security) designed for UDP traffic, the fast, loss-tolerant protocol used by real-time applications like WebRTC video calls and voice-over-IP connections. Because UDP does not guarantee delivery, DTLS includes a timer that resends handshake messages if no acknowledgment arrives. The vulnerability surfaces when a resend is triggered while a large handshake message is still in the process of being sent in fragments.

OpenSSL splits oversized handshake messages into chunks that each fit inside a single UDP datagram. If the connection cannot accept more data for a moment, sending may pause partway through a message. Before the fix, if the resend timer fired during such a pause, the code wrongly used the buffer position of the paused, larger message instead of returning to the start of the original message. That caused the resent message to carry an incorrect label and fill its payload with leftover bytes from the oversized message, effectively spilling raw heap memory as unencrypted handshake data. In some cases the buffer overread reached unmapped memory and caused an abrupt crash.

Every OpenSSL branch from 1.0.2 through 4.0 is affected before its respective fixed release. Public updates are available for the actively supported lines: users should upgrade to OpenSSL 4.0.3, 3.6.5, 3.5.9, or 3.4.8. For the older 3.0, 1.1.1, and 1.0.2 series, security patches are now limited to premium support customers, since public support for 3.0 ended on September 7. Ubuntu has already shipped the fix in its distribution packages: Ubuntu 26.04 LTS subscribers get libssl3t64 3.5.5-1ubuntu3.6, 24.04 LTS gets 3.0.13-0ubuntu3.16, and 22.04 LTS gets 3.0.2-0ubuntu1.30. Debian 13 resolved the issue with package version 3.5.7-1~deb13u3 (DSA-6531-1). A reboot is required after applying these updates so that all running processes load the corrected library.

The September 29 release also addresses 13 other CVEs. The most notable beyond the high-severity DTLS leak is CVE-2026-84783, a moderate flaw that affects only OpenSSL 4.0. It can allow a remote, unauthenticated peer to crash a multi-threaded TLS client or a server that requests client certificates, but only when several connections build certificate chains to the same trusted CA certificate simultaneously. Another DTLS issue, CVE-2026-75806 (rated low), permits an attacker to tear down an established DTLS 1.2 connection with a single short datagram without knowing any encryption keys. The remaining eleven flaws are all low severity and include five bugs in OpenSSL's QUIC code and three timing side-channel vulnerabilities in ECDSA and SM2 cryptographic routines.

For website owners and businesses that rely on secure server environments, the quick patching of foundational libraries like OpenSSL is critical. A managed hosting service that handles proactive security updates can lift that burden. AEU Hosting, which provides managed WordPress hosting with end-to-end security, ensures that the server software stack, including OpenSSL, stays updated as fixes appear, helping site operators avoid exposure to flaws like this one.

The flaw was reported on August 17 by Laurent Gaffie of Secorizon, and the fix was developed by Ryan Hooper. OpenSSL has not said whether an attacker can deliberately cause the resend-while-stuck condition, and no active exploitation has been observed. CISA assigned the flaw a CVSS score of 8.2 out of 10 (high), rating the confidentiality impact low and the availability impact high. There is no workaround; users who cannot update and are affected should plan to upgrade or obtain a premium support contract.

Come Proteggerti

  1. If you run a website on a server that uses OpenSSL, contact your hosting provider to confirm they have applied the September 29 security update.
  2. Install all available system updates on your Linux computer or server now – Ubuntu and Debian already include the OpenSSL fix.
  3. Restart your computer or any application that relies on encrypted real-time communication after installing the updates so the patched library loads.
  4. Keep your operating system set to automatic updates so critical fixes like this arrive without delay.
  5. If you use video calling or voice-over-IP apps that depend on DTLS, make sure you have updated those apps to their latest versions.

Vulnerabilità e Soluzioni

I Termini Spiegati

  • OpenSSL A widely used software library that gives apps the ability to encrypt internet communication so data stays private and unaltered.
  • DTLS Datagram Transport Layer Security, an encryption protocol for applications that use UDP, such as video calls and live streaming, where speed matters more than perfect reliability.
  • heap memory A flexible storage area inside a running program that holds temporary data; if it leaks to an outsider, sensitive information can be exposed.
  • UDP User Datagram Protocol, a lightweight, connectionless network protocol often chosen for real-time audio and video because it reduces delay.
  • CVE Common Vulnerabilities and Exposures, a catalogue that gives unique numbers to publicly known security weaknesses so everyone can refer to the same flaw.

Servizi AEU correlati