OpenSSL Security Advisory [29th September 2026]
OpenSSL rates DTLS handshake retransmission bug CVE-2026-84782 high severity.
OpenSSL published a September 29, 2026 security advisory rating CVE-2026-84782 high severity. DTLS retransmission does not correctly handle a handshake message write that is suspended part-way through, so a retransmitted message can be read from a stale buffer offset. The oss-security post does not report active exploitation.
- CVE-2026-84782 is rated high in OpenSSL's September 29 advisory.
- DTLS retransmission can use a stale buffer offset after a suspended handshake write.
- The posted excerpt does not say the bug is being exploited.
Vulnerabilities mentionedAll →
- CVE-2026-847828.2—OpenSSL DTLS retransmission out-of-bounds read leaks heap or crashespublished · OpenSSL
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-84782 | OpenSSL DTLS retransmission out-of-bounds read leaks heap or crashes OpenSSL’s DTLS retransmission logic mishandles a handshake message write that is suspended part-way through, which is an out-of-bounds read (CWE-125). If the underlying transport returns WANT_WRITE mid-message and the retransmission timer then fires, the resend reuses the suspended write’s buffer and position, so the message body can be leftover bytes from a larger in-flight message and can be read past the allocated buffer. A DTLS peer can receive that leftover heap memory as plaintext handshake data, or the process can crash and cause a denial of service if the read hits unmapped memory; separately, completing a retransmission while a write is suspended corrupts shared bookkeeping and can abort the process in a debugging build when SSL_read, SSL_write, SSL_accept, or SSL_connect later resumes the write. Applications and devices that use OpenSSL for DTLS handshakes are affected; the issue is outside the FIPS module boundary. There is no known public proof of concept and the CVE is not listed in CISA KEV. |
Posted by Tomas Mraz on Sep 29 OpenSSL Security Advisory [29th September 2026] =============================================== DTLS Retransmits Handshake Messages From a Stale Buffer Offset (CVE-2026-84782) =============================================================================== Severity: High Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read past...
This source does not provide full text. Read it at seclists.org.