Out-of-bounds Read Vulnerability in OpenSSL DTLS Handshake Logic
CVE-2026-84782
Currently unrated
What is CVE-2026-84782?
This vulnerability in OpenSSL's DTLS implementation arises from inadequate handling of handshake messages during retransmissions. When a write is interrupted, the retransmission logic fails to reset the internal buffer position effectively, potentially leading to the disclosure of sensitive heap memory as plaintext data. Furthermore, it can also lead to application crashes and Denial of Service by attempting to read from unmapped memory regions. The oversight in the retransmission handling can severely compromise the integrity of DTLS connections, making it crucial to address this flaw promptly through available patches.
Affected Version(s)
OpenSSL 4.0.0 < 4.0.3
OpenSSL 3.6.0 < 3.6.5
OpenSSL 3.5.0 < 3.5.9