Out-of-bounds Read Vulnerability in OpenSSL DTLS Handshake Logic
CVE-2026-84782

Currently unrated

Key Information:

Vendor

OpenSSL

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-84782?

This vulnerability in OpenSSL's DTLS implementation arises from inadequate handling of handshake messages during retransmissions. When a write is interrupted, the retransmission logic fails to reset the internal buffer position effectively, potentially leading to the disclosure of sensitive heap memory as plaintext data. Furthermore, it can also lead to application crashes and Denial of Service by attempting to read from unmapped memory regions. The oversight in the retransmission handling can severely compromise the integrity of DTLS connections, making it crucial to address this flaw promptly through available patches.

Affected Version(s)

OpenSSL 4.0.0 < 4.0.3

OpenSSL 3.6.0 < 3.6.5

OpenSSL 3.5.0 < 3.5.9

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Laurent Gaffie (secorizon.com)
Ryan Hooper
.