OpenSSL Fixes High-Severity Bug That Can Leak Server Memory in Plaintext
OpenSSL patched CVE-2026-84782, a high-severity DTLS flaw that can leak heap memory or crash servers.
OpenSSL patched CVE-2026-84782, a high-severity out-of-bounds read in DTLS handshake retransmission disclosed on September 29, 2026. A stale read offset can attach leftover bytes and send adjacent heap memory to a peer as plaintext, or crash the process if the read hits unmapped memory. All branches are affected, including 4.0 before 4.0.3, 3.6 before 3.6.5, 3.5 before 3.5.9, and 3.4 before 3.4.8; older 3.0, 1.1.1, and 1.0.2 fixes are limited to premium support. FIPS modules are outside the affected boundary, and OpenSSL 4.0.3 also addresses 13 additional issues.
- CVE-2026-84782 is an out-of-bounds read in DTLS handshake retransmission.
- The bug can send adjacent heap memory as plaintext or crash the process.
- Fixes are in OpenSSL 4.0.3, 3.6.5, 3.5.9, 3.4.8, and older premium branches.
- FIPS modules are unaffected; bundled OpenSSL copies may still be exposed.
- OpenSSL 4.0.3 also fixes 13 other vulnerabilities.
Vulnerabilities mentionedAll →
- CVE-2026-847828.2—OpenSSL DTLS retransmission out-of-bounds read leaks heap or crashespublished · OpenSSL
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-84782 | OpenSSL DTLS retransmission out-of-bounds read leaks heap or crashes OpenSSL’s DTLS retransmission logic mishandles a handshake message write that is suspended part-way through, which is an out-of-bounds read (CWE-125). If the underlying transport returns WANT_WRITE mid-message and the retransmission timer then fires, the resend reuses the suspended write’s buffer and position, so the message body can be leftover bytes from a larger in-flight message and can be read past the allocated buffer. A DTLS peer can receive that leftover heap memory as plaintext handshake data, or the process can crash and cause a denial of service if the read hits unmapped memory; separately, completing a retransmission while a write is suspended corrupts shared bookkeeping and can abort the process in a debugging build when SSL_read, SSL_write, SSL_accept, or SSL_connect later resumes the write. Applications and devices that use OpenSSL for DTLS handshakes are affected; the issue is outside the FIPS module boundary. There is no known public proof of concept and the CVE is not listed in CISA KEV. |
Full article621 words · extracted from cybersecuritynews.com · click to collapse
OpenSSL has released security updates for a high-severity vulnerability that could expose heap memory as plaintext during Datagram Transport Layer Security (DTLS) handshakes.
Tracked as CVE-2026-84782, the flaw stems from an out-of-bounds read in DTLS handshake retransmission logic and can also crash an affected process, creating a denial-of-service condition.
The OpenSSL Project disclosed the issue on September 29, 2026, alongside security releases OpenSSL 4.0.3, 3.6.5, 3.5.9 and 3.4.8. OpenSSL described those releases as security patches and said the most severe vulnerability corrected in each is rated High.
OpenSSL Leak Server Memory
DTLS provides TLS-style security over unreliable datagram transports, where packets may be delayed, reordered, or lost. Consequently, its handshake layer can fragment large messages and retransmit previously sent data when a timer expires.
CVE-2026-84782 emerges when OpenSSL suspends a handshake-message write partway through because its transport cannot accept more data, returning WANT_WRITE.
While that write remains suspended, a retransmission timer can request that an earlier handshake message be sent again. Vulnerable OpenSSL versions reused the internal buffer and position tracking associated with the interrupted write but failed to reset the read offset to the beginning of the queued message.
The retransmission could therefore begin at a stale position, attach leftover bytes from a different, larger message, and continue reading beyond the allocated buffer.
That behavior may send adjacent heap contents to the connected peer as plaintext handshake data. The exposed bytes depend on nearby process memory contents, so the advisory does not define a fixed set of secrets that will always leak.
If the out-of-bounds flaw impacts an unmapped memory region, the process may instead terminate, allowing a peer to trigger denial of service. OpenSSL classifies the weakness as CWE-125, an out-of-bounds read.
The bug creates a second state-management problem. Even when retransmission starts at the correct offset, completing it while another handshake write is paused overwrites shared bookkeeping needed to resume the original operation. A later SSL_read(), SSL_write(), SSL_accept() or SSL_connect() call can then encounter state inconsistent with the suspended message; OpenSSL says this causes an abort in debugging builds.
OpenSSL fixed the vulnerability by resetting the retransmission read position before resending a message. The code also skips retransmission while a handshake write remains suspended, deferring work until a later call resumes it. The affected logic sits outside the OpenSSL FIPS module boundary, so the project says FIPS modules are not impacted.
All branches are vulnerable: OpenSSL 4.0 before 4.0.3, 3.6 before 3.6.5, 3.5 before 3.5.9, 3.4 before 3.4.8, 3.0 before 3.0.23, 1.1.1 before 1.1.1zj and 1.0.2 before 1.0.2zs. Fixes for the three oldest branches are limited to premium support customers.
Administrators should inventory appliances, embedded systems, VPN products, and applications that use OpenSSL DTLS, then upgrade through their operating-system or product vendor.
Updating to 4.0.3, 3.6.5, 3.5.9 or 3.4.8 addresses the issue on maintained branches, while supported customers should obtain 3.0.23, 1.1.1zj or 1.0.2zs. Because applications may bundle OpenSSL rather than use the system library, checking only the host package manager may miss exposed copies.
Laurent Gaffie of Secorizon reported CVE-2026-84782 on August 17, 2026, and Ryan Hooper developed the correction after receiving the report in August.
OpenSSL 4.0.3 also addresses 13 additional vulnerabilities affecting X.509 processing, QUIC, CMP, DTLS, SM2, and elliptic-curve operations, reinforcing the need to treat this release as a security update rather than a single-bug patch.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.