High-Severity OpenSSL Flaw Exposes Heap Memory, Prompts Urgent Patching
A critical high-severity vulnerability in **OpenSSL**'s DTLS implementation, tracked as **CVE-2026-84782**, has been disclosed, enabling potential heap memory leakage or program crashes. The flaw affects numerous **OpenSSL** versions, with patches now available, though older branches require premium support. IT security professionals and privacy-conscious users are urged to update immediately to mitigate risks.
A high-severity flaw in **OpenSSL**'s Datagram Transport Layer Security (**DTLS**) implementation could lead to the leakage of heap memory or program crashes, the **OpenSSL** project announced on September 29, coinciding with the release of essential fixes.
**DTLS**, the variant of **TLS** designed for UDP traffic, is susceptible to this vulnerability when a handshake message resend is initiated while a larger message is partially transmitted. This timing conflict can expose sensitive information or cause service disruption.
### The Vulnerability: CVE-2026-84782
The flaw, identified as **CVE-2026-84782**, has been addressed in **OpenSSL** versions **4.0.3**, **3.6.5**, **3.5.9**, and **3.4.8**. Users of older branches, specifically **3.0**, **1.1.1**, and **1.0.2**, will only receive fixes if they are **OpenSSL** premium support customers, as public security support for **OpenSSL 3.0** ended on September 7.
**OpenSSL** has not confirmed whether attackers can actively exploit this resend timing issue, nor have any in-the-wild attacks been reported. However, the potential for exploitation remains a significant concern.
### Impact and Technical Details
**DTLS** is commonly employed to secure **WebRTC** data channels and establish encryption keys for internet-based calls. Software is only at risk if it leverages **OpenSSL** for **DTLS** functionality.
The mechanism of the flaw involves **DTLS** fragmenting large handshake messages into smaller UDP datagrams. If the connection temporarily halts data transmission, sending can pause mid-message. During this pause, the resend timer can still trigger, sending an earlier message again.
Prior to the fix, the resend operation incorrectly used the paused message's buffer position instead of reverting to the start of the message being resent. This resulted in the resent message being sent with an erroneous label, its body containing leftover bytes from the larger, partially sent message. This could lead to a buffer overrun.
This mislabeled message can inadvertently transmit heap memory to the receiving end as unencrypted handshake data. If the read operation accesses unmapped memory, it can cause the program to crash, leading to a denial of service.
The vulnerability is not limited to either **DTLS** clients or servers, and the provided fix has been thoroughly tested in both roles.
**Laurent Gaffie** of **Secorizon** is credited with reporting the flaw on August 17, with **Ryan Hooper** developing the patch.
### Severity and Recommendations
**OpenSSL** has rated this flaw as High severity, just below Critical on its internal scale. Their security policy strongly advises immediate installation of updates for High-severity fixes.
**CISA** assigned **CVE-2026-84782** a **CVSS score of 8.2** out of 10 on September 29, indicating a Low impact on confidentiality and a High impact on availability. At the time of their assessment, no exploitation was listed. It's worth noting that **OpenSSL**'s severity ratings are independent of **CVSS** scores.
**Ubuntu**'s security notice for the flaw suggests that an attacker could potentially cause "incorrect handshake behavior or a denial of service," though it does not explicitly mention memory leakage.
### Patching Information

The flaw impacts **OpenSSL** versions **4.0**, **3.6**, **3.5**, **3.4**, **3.0**, **1.1.1**, and **1.0.2**, specifically any release prior to the fixed versions:
| Branch | Fixed version | Who can get it | Support status |
|---|---|---|---|
| **4.0** | **4.0.3** | Public download | Supported until May 14, 2027 |
| **3.6** | **3.6.5** | Public download | Supported until November 1, 2026 |
| **3.5** | **3.5.9** | Public download | Long-term support release, supported until April 8, 2030 |
| **3.4** | **3.4.8** | Public download | Supported until October 22, 2026 |
| **3.0** | **3.0.23** | Premium support customers only | Public support ended September 7, 2026 |
| **1.1.1** | **1.1.1zj** | Premium support customers only | No public support |
| **1.0.2** | **1.0.2zs** | Premium support customers only | No public support |
| **3.1, 3.2, 3.3** | None listed | Not applicable | No public support. OpenSSL did not check whether these branches are affected. |
No workaround is currently available for users unable to update immediately. However, **Ubuntu** released fixes for its packages on September 29:
* **Ubuntu 26.04 LTS**: `libssl3t64 3.5.5-1ubuntu3.6`
* **Ubuntu 24.04 LTS**: `libssl3t64 3.0.13-0ubuntu3.16`
* **Ubuntu 22.04 LTS**: `libssl3 3.0.2-0ubuntu1.30`
**Ubuntu** users are advised to reboot their systems after applying the update for the changes to take full effect.
**Debian** has also addressed the flaw in **Debian 13** with version `3.5.7-1~deb13u3` of its **openssl** package, released as **DSA-6531-1**. As of September 30, **Debian 12** was still listed as vulnerable.
### Advice for OpenSSL 3.0 Users
For those running **OpenSSL 3.0**, the last public release was **3.0.22** on August 25. Version **3.0.23** is the first **3.0** security release not publicly available, addressing 6 of the 14 flaws disclosed on September 29, including **CVE-2026-84782**.
While **Ubuntu 22.04** and **24.04** users, which utilize **OpenSSL 3.0**, have fixes available through their distribution's packages, anyone who builds **OpenSSL 3.0** independently or bundles it within their software will not receive a public fix directly from **OpenSSL**.
**OpenSSL** strongly recommends upgrading to a newer, publicly supported branch like **4.0** or the long-term support release **3.5**. Alternatively, organizations can opt for a paid support contract to gain continued access to security fixes for older, end-of-life releases.
### Other Patched Vulnerabilities
The September 29 releases also address 13 other vulnerabilities. The most significant among these is **CVE-2026-84783**, rated Moderate severity, which impacts only **OpenSSL 4.0**. This flaw could allow a remote, unauthenticated peer to crash a multi-threaded **TLS** client or a multi-threaded **TLS** server requesting client certificates, under specific conditions where multiple connections build certificate chains to the same trusted **CA** certificate simultaneously.
Another **DTLS** flaw, **CVE-2026-75806**, rated Low, affects established **DTLS 1.2** connections using an **AEAD** cipher suite. This vulnerability allows an attacker to terminate such a connection with a single, malformed datagram without needing to know any keys.
The remaining 11 flaws are also rated Low, including 5 in **OpenSSL**'s **QUIC** code and 3 timing side-channel vulnerabilities in **ECDSA** and **SM2** code.