OpenSSL High-Severity Flaw Lets Attackers Leak Heap Memory in Plaintext
OpenSSL patched high-severity CVE-2026-84782, a DTLS out-of-bounds read that can leak heap memory or crash services.
OpenSSL disclosed CVE-2026-84782, a high-severity out-of-bounds read (CWE-125) in DTLS handshake retransmission handling. When a fragmented handshake write is suspended with WANT_WRITE, retransmission can reuse the same buffer at the wrong offset, sending leftover heap bytes to a remote peer or crashing on an unmapped read. Affected branches are 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1, and 1.0.2, fixed in 4.0.3, 3.6.5, 3.5.9, 3.4.8, 3.0.23, 1.1.1zj, and 1.0.2zs. The FIPS module is unaffected, and the advisory does not confirm reliable arbitrary-memory disclosure or in-the-wild exploitation.
- CVE-2026-84782 is a DTLS out-of-bounds read during handshake retransmission.
- Remote peers may receive leftover heap plaintext or trigger a crash.
- Fixed releases include OpenSSL 4.0.3, 3.6.5, 3.5.9, 3.4.8, and 3.0.23.
- The OpenSSL FIPS module is outside the vulnerable code path.
Vulnerabilities mentionedAll →
- CVE-2026-847828.2—OpenSSL DTLS retransmission out-of-bounds read leaks heap or crashespublished · OpenSSL
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-84782 | OpenSSL DTLS retransmission out-of-bounds read leaks heap or crashes OpenSSL’s DTLS retransmission logic mishandles a handshake message write that is suspended part-way through, which is an out-of-bounds read (CWE-125). If the underlying transport returns WANT_WRITE mid-message and the retransmission timer then fires, the resend reuses the suspended write’s buffer and position, so the message body can be leftover bytes from a larger in-flight message and can be read past the allocated buffer. A DTLS peer can receive that leftover heap memory as plaintext handshake data, or the process can crash and cause a denial of service if the read hits unmapped memory; separately, completing a retransmission while a write is suspended corrupts shared bookkeeping and can abort the process in a debugging build when SSL_read, SSL_write, SSL_accept, or SSL_connect later resumes the write. Applications and devices that use OpenSSL for DTLS handshakes are affected; the issue is outside the FIPS module boundary. There is no known public proof of concept and the CVE is not listed in CISA KEV. |
Full article574 words · extracted from gbhackers.com · click to collapse
OpenSSL has announced a high-severity vulnerability in its Datagram Transport Layer Security (DTLS) implementation that could allow a remote peer to read unintended plaintext heap memory during handshake data transmission or trigger a denial-of-service condition.
This vulnerability, tracked as CVE-2026-84782, stems from an out-of-bounds read when handling DTLS handshake message retransmissions.
The issue affects various OpenSSL versions, including 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1, and 1.0.2, as noted in the OpenSSL Security Advisory released on September 29, 2026.
OpenSSL High-Severity Flaw
DTLS is specifically designed for datagram-based transports and incorporates retransmission mechanisms to recover handshake packets that may be lost in transit.
The vulnerability occurs when an application sends a DTLS handshake message in multiple fragments, and the transport temporarily cannot accept more data.
In this case, OpenSSL may return a WANT_WRITE status, which suspends the handshake message write midway through transmission.
While this operation is suspended, a DTLS retransmission timer can expire and attempt to resend an earlier handshake message from the retransmission queue.
OpenSSL’s retransmission logic mistakenly reuses the same internal buffer and tracking state associated with the suspended handshake write.
Instead of resetting its read position to the beginning of the queued message, retransmission could start at the offset reached during the in-progress write.
Consequently, a peer might receive a malformed or mislabeled DTLS handshake message containing leftover bytes from an unrelated, larger message still in transit. In some cases, this can lead to reading beyond the intended message buffer, which could expose heap-resident data in plaintext.
This vulnerability is classified as CWE-125, indicating an out-of-bounds read weakness. Its primary security concern is the unintended disclosure of heap memory to the remote DTLS peer.
The leaked data will vary based on the process’s memory contents and runtime conditions, potentially including fragments of previously allocated application or library data. However, the advisory has not confirmed any reliable arbitrary-memory disclosure capability.
Moreover, the flaw can also cause a process to crash when the retransmission logic attempts to read from an unmapped memory region, potentially causing a denial-of-service condition for affected applications handling attacker-controlled DTLS traffic.
A related flaw within the same retransmission path could corrupt the bookkeeping necessary to resume the suspended handshake write. If retransmission occurs while another write is still paused, any subsequent calls to SSL_read(), SSL_write(), SSL_accept(), or SSL_connect() may encounter inconsistent states, triggering an abort in debugging builds.
Affected Versions and Fixes
OpenSSL has addressed the issue by resetting the retransmission read position before resending a message. The project also ensures that retransmissions are skipped while a handshake write is suspended, deferring them until the application resumes the pending operation.
| Affected branch | Fixed release |
|---|---|
| OpenSSL 4.0 | 4.0.3 |
| OpenSSL 3.6 | 3.6.5 |
| OpenSSL 3.5 | 3.5.9 |
| OpenSSL 3.4 | 3.4.8 |
| OpenSSL 3.0 Premium Support | 3.0.23 |
| OpenSSL 1.1.1 Premium Support | 1.1.1zj |
| OpenSSL 1.0.2 Premium Support | 1.0.2zs |
Organizations should identify internet-facing services, VPNs, VoIP systems, IoT deployments, and custom applications using DTLS, and promptly upgrade their bundled or system-provided OpenSSL packages. This issue does not affect the OpenSSL FIPS module, as the vulnerable DTLS code lies outside its boundary.
The vulnerability was reported on August 17, 2026, by Laurent Gaffie of SecuRizon, and Ryan Hooper developed the fix.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.