Denial of Service Vulnerability in OpenSSL DTLS 1.2
CVE-2026-75806
Currently unrated
What is CVE-2026-75806?
A vulnerability exists in OpenSSL's DTLS 1.2 protocol where an unauthenticated datagram can terminate an existing secure association. This issue arises because the system fails to properly validate the length of incoming encrypted fragments, allowing attackers to disrupt services without needing any key material. The failure in handling such records can lead to internal error alerts, leading to service interruptions. To mitigate this vulnerability, updates have been released to ensure proper validation of record lengths before processing, allowing for secure handling of unauthorized packets.
Affected Version(s)
OpenSSL 4.0.0 < 4.0.3
OpenSSL 3.6.0 < 3.6.5
OpenSSL 3.5.0 < 3.5.9