OpenSSL DTLS retransmission out-of-bounds read leaks heap or crashes
CVSS 3.1
8.2high
EPSS
—
Published
()
Modified
AI analysis
OpenSSL’s DTLS retransmission logic mishandles a handshake message write that is suspended part-way through, which is an out-of-bounds read (CWE-125). If the underlying transport returns WANT_WRITE mid-message and the retransmission timer then fires, the resend reuses the suspended write’s buffer and position, so the message body can be leftover bytes from a larger in-flight message and can be read past the allocated buffer. A DTLS peer can receive that leftover heap memory as plaintext handshake data, or the process can crash and cause a denial of service if the read hits unmapped memory; separately, completing a retransmission while a write is suspended corrupts shared bookkeeping and can abort the process in a debugging build when SSL_read, SSL_write, SSL_accept, or SSL_connect later resumes the write. Applications and devices that use OpenSSL for DTLS handshakes are affected; the issue is outside the FIPS module boundary. There is no known public proof of concept and the CVE is not listed in CISA KEV.
What to do: Install the OpenSSL update from the 29 September 2026 security advisory as soon as your vendor or distribution ships it; the fix resets the retransmission read position and skips retransmission while a handshake write is still suspended. Until then, limit DTLS listeners and clients to trusted peers and networks, and watch for process crashes during DTLS handshakes. FIPS module boundaries are not implicated, but non-FIPS OpenSSL builds that perform DTLS handshakes still need the fix.
Affected
OpenSSL
Version ranges were not included in the advisory data; the flaw is in DTLS handshake retransmission handling, outside the FIPS module boundary
Estimated exposure
largeHundreds of thousands to low millions of DTLS-capable OpenSSL endpoints (estimate) — OpenSSL is the default TLS/DTLS library on most Linux distributions and many appliances and embedded stacks, so total installs are far above 100,000 systems; only endpoints that actually run DTLS handshakes can hit this bug, and no…
Description
Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read past the message buffer and the retransmission overwrites the internal state the suspended write needs to resume correctly. Impact summary: The retransmitted message can disclose a heap memory to the peer as plaintext handshake data or cause a crash and a Denial of Service when the read reaches an unmapped memory region. CWE: CWE-125: Out-of-bounds Read Description: DTLS handshake messages can be written out in multiple fragments, and a write can suspend mid-message (returning WANT_WRITE) if the underlying transport temporarily cannot accept more data. While such a write is suspended, the DTLS retransmission timer may independently fire and ask the retransmission logic to resend an earlier, already-acknowledged-as-sent message from its retransmit queue. The retransmission logic reused the same internal buffer and position tracking as the message that was still being written, without resetting the position back to the start of the message being retransmitted. As a result the retransmission was read starting from wherever the suspended write had left off, producing a mislabelled message whose body was leftover bytes from the other, larger message still in flight - content that was never meant to be sent at that point, and which could run past the end of the allocated buffer. Separately, even when the retransmission is positioned correctly, allowing it to run to completion while another write is suspended overwrites the same shared bookkeeping that the suspended write depends on to resume. When the application later resumes the suspended write (via a subsequent SSL_read(), SSL_write(), SSL_accept(), or SSL_connect() call), it finds that bookkeeping in a state inconsistent with the message and aborts the process in a debugging build. The fix resets the retransmission's read position to the start of the message before resending, and skips retransmission entirely whenever a handshake write is still suspended, deferring to the next call that resumes it instead. FIPS impact: no The affected code is outside the FIPS module boundary.
OpenSSL patched high-severity CVE-2026-84782, a DTLS out-of-bounds read that can leak heap memory or crash services.
OpenSSL disclosed CVE-2026-84782, a high-severity out-of-bounds read (CWE-125) in DTLS handshake retransmission handling. When a fragmented handshake write is suspended with WANT_WRITE, retransmission can reuse the same buffer at the wrong offset, sending leftover heap bytes to a remote peer or crashing on an unmapped read. Affected branches are 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1, and 1.0.2, fixed in 4.0.3, 3.6.5, 3.5.9, 3.4.8, 3.0.23, 1.1.1zj, and 1.0.2zs. The FIPS module is unaffected, and the advisory does not confirm reliable arbitrary-memory disclosure or in-the-wild exploitation.
OpenSSL patched CVE-2026-84782, a high-severity DTLS flaw that can leak heap memory or crash servers.
OpenSSL patched CVE-2026-84782, a high-severity out-of-bounds read in DTLS handshake retransmission disclosed on September 29, 2026. A stale read offset can attach leftover bytes and send adjacent heap memory to a peer as plaintext, or crash the process if the read hits unmapped memory. All branches are affected, including 4.0 before 4.0.3, 3.6 before 3.6.5, 3.5 before 3.5.9, and 3.4 before 3.4.8; older 3.0, 1.1.1, and 1.0.2 fixes are limited to premium support. FIPS modules are outside the affected boundary, and OpenSSL 4.0.3 also addresses 13 additional issues.
OpenSSL rates DTLS handshake retransmission bug CVE-2026-84782 high severity.
OpenSSL published a September 29, 2026 security advisory rating CVE-2026-84782 high severity. DTLS retransmission does not correctly handle a handshake message write that is suspended part-way through, so a retransmitted message can be read from a stale buffer offset. The oss-security post does not report active exploitation.
OpenSSL patches high-severity DTLS flaw CVE-2026-84782 (CVSS 8.2) that can leak unencrypted heap memory or crash DTLS connections.
CVE-2026-84782 is a high-severity OpenSSL flaw where a DTLS handshake message resend during a paused larger message send can transmit mislabeled data containing heap memory as unencrypted handshake data, or crash on unmapped memory. Fixes are available in OpenSSL 4.0.3, 3.6.5, 3.5.9 and 3.4.8, while 3.0, 1.1.1 and 1.0.2 fixes are limited to premium support customers. CISA assigned CVSS 8.2 and listed exploitation as none. The September 29 releases also fix 13 other flaws, including moderate CVE-2026-84783 (crash in multithreaded TLS) and low CVE-2026-75806 (DTLS 1.2 AEAD connection reset).
OpenSSL and wolfSSL patched roughly 25 vulnerabilities, including an 8.2-rated DTLS heap data leak and certificate authentication bypasses affecting Nginx and HAProxy builds.
OpenSSL fixed 14 flaws, led by CVE-2026-84782 (CVSS 8.2), which lets an unauthenticated remote peer obtain heap memory fragments or crash DTLS applications common in VPNs, VoIP and IoT products. wolfSSL 5.9.4 patches 11 vulnerabilities including three high-severity authentication bypasses (CVE-2026-93302, CVE-2026-89102, CVE-2026-89136) enabling server impersonation and forged certificates. Remaining flaws mainly cause DoS, QUIC DDoS amplification, or timing side-channel leaks relevant to private key recovery. No exploitation was reported.