OpenSSL bug leaks unencrypted memory in DTLS connections
DTLS users who depend on OpenSSL for secure UDP traffic now face a serious security problem. A new bug, CVE-2026-84782, can leak unencrypted heap memory over a DTLS connection. It can also crash the app. This hits the heart of encrypted traffic.
OpenSSL's patch set on September 29, 2026, addressed a total of 14 vulnerabilities, with CVE-2026-84782 identified as the most severe among them.
Laurent Gaffie from Secorizon reported the bug on August 17. Ryan Hooper wrote the fix. OpenSSL released patched versions-4.0.3, 3.6.5, 3.5.9, and 3.4.8-on September 29. But users on older branches like 3.0, 1.1.1, and 1.0.2 are stuck. Only those with premium support can get the fix. Public support for OpenSSL 3.0 ended September 7. The latest 3.0.23 release is now behind a paywall. Many open-source and enterprise systems are exposed unless they move to a newer branch.
DTLS secures WebRTC data channels and sets up encryption keys for internet calls. This bug is a real threat to live communications. The cause is simple. DTLS splits big handshake messages into UDP-sized chunks. If sending pauses, a resend timer can fire. Instead of sending the right message, the protocol may send leftover bytes from the buffer. This can leak sensitive heap data, unencrypted, to the other side.
The vulnerability is considered remotely exploitable over the network without authentication or user interaction, and is rated as high severity with a CVSS score of 8.2.
OpenSSL has not said if attackers can reliably trigger the resend bug. No attacks in the wild have been reported. Still, the project's security policy is blunt. Install updates with High-rated fixes right away. Ubuntu and Debian have already shipped patched packages. Ubuntu users must reboot for the fix to work. Debian 13 is patched. Debian 12 is still vulnerable as of September 30.
Stuck on OpenSSL 3.0? The risk is higher. The last public release, 3.0.22, does not have the fix. Only Ubuntu's packages for 22.04 and 24.04 LTS include the patch. Anyone building or bundling OpenSSL 3.0 from source has no public fix. OpenSSL's advice is simple. Upgrade to a supported branch like 4.0 or 3.5, or pay for premium support to get security fixes.
This update also fixes 13 other bugs. One is a Moderate-rated flaw (CVE-2026-84783) that can crash multi-threaded TLS clients or servers in rare certificate chain cases. Another is a Low-rated DTLS 1.2 bug (CVE-2026-75806) that lets a connection end with a single too-short datagram. The rest are Low, affecting QUIC code and cryptographic timing side-channels.
This OpenSSL crisis shows the risk for anyone slow to update or stuck on unsupported branches. The project now limits fixes for old versions to paying customers. That leaves much of the open-source world exposed. In this threat landscape, there are only two choices. Upgrade now, or accept the risk of running unpatched crypto software. Anything else is a gamble with secure communications.