AI Weekly Malaysia

Back to items Summaries

OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted

ID
30232
Status
summarized
Published
30 Sep 2026, 4:09 PM
Fetched
30 Sep 2026, 6:48 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/openssl-fixes-high-severity-dtls-flaw.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
6.0
Created
30 Sep 2026, 6:49 PM
Tags
Audience
developerssaas_startup_founders

What happened

OpenSSL patched CVE-2026-84782, a High-severity DTLS bug where a resend timer firing mid-message causes an earlier handshake message to be re-sent with the wrong label, leaking leftover heap bytes to the peer as unencrypted handshake data or crashing the process on unmapped memory reads. Fixes shipped September 29 in OpenSSL 4.0.3, 3.6.5, 3.5.9 and 3.4.8; the older 3.0, 1.1.1 and 1.0.2 branches get fixes only for paying premium-support customers, and 3.0 stopped receiving public security fixes on September 7. CISA scored it CVSS 8.2 (confidentiality Low, availability High); Secorizon's Laurent Gaffie reported it August 17, Ryan Hooper wrote the fix, and OpenSSL reports no known exploitation.

Why it matters

Only code that runs DTLS over OpenSSL is exposed — think WebRTC data channels, TURN/media servers, VoIP key setup, IoT and UDP-based services — so check whether those components are in your stack before treating this as urgent for your whole fleet. The sharper decision is version lifecycle: if you are still on OpenSSL 3.0, 1.1.1 or 1.0.2, this patch is behind premium support, so the choice is pay, migrate to a 3.4+/3.6/4.0 branch, or knowingly run unpatched against this and every future High fix.

Discussion angle

Inventory check live: who in the room is still on OpenSSL 3.0/1.1.1/1.0.2, and does anything you run actually terminate DTLS (WebRTC, TURN, SIP/VoIP, media relays)? That determines whether this is a this-week patch or a migration-planning item.

Top