OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted
- ID
- 30232
- Status
- summarized
- Published
- 30 Sep 2026, 4:09 PM
- Fetched
- 30 Sep 2026, 6:48 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/openssl-fixes-high-severity-dtls-flaw.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 6.0
- Created
- 30 Sep 2026, 6:49 PM
- Tags
- Audience
- developerssaas_startup_founders
What happened
OpenSSL patched CVE-2026-84782, a High-severity DTLS bug where a resend timer firing mid-message causes an earlier handshake message to be re-sent with the wrong label, leaking leftover heap bytes to the peer as unencrypted handshake data or crashing the process on unmapped memory reads. Fixes shipped September 29 in OpenSSL 4.0.3, 3.6.5, 3.5.9 and 3.4.8; the older 3.0, 1.1.1 and 1.0.2 branches get fixes only for paying premium-support customers, and 3.0 stopped receiving public security fixes on September 7. CISA scored it CVSS 8.2 (confidentiality Low, availability High); Secorizon's Laurent Gaffie reported it August 17, Ryan Hooper wrote the fix, and OpenSSL reports no known exploitation.
Why it matters
Only code that runs DTLS over OpenSSL is exposed — think WebRTC data channels, TURN/media servers, VoIP key setup, IoT and UDP-based services — so check whether those components are in your stack before treating this as urgent for your whole fleet. The sharper decision is version lifecycle: if you are still on OpenSSL 3.0, 1.1.1 or 1.0.2, this patch is behind premium support, so the choice is pay, migrate to a 3.4+/3.6/4.0 branch, or knowingly run unpatched against this and every future High fix.
Discussion angle
Inventory check live: who in the room is still on OpenSSL 3.0/1.1.1/1.0.2, and does anything you run actually terminate DTLS (WebRTC, TURN, SIP/VoIP, media relays)? That determines whether this is a this-week patch or a migration-planning item.