Oct 02, 2026 DISPATCH // HARDWARE, CODE & PLATFORMS

OpenSSL bug leaks unencrypted memory in DTLS connections

A major OpenSSL bug can leak unencrypted heap memory or crash DTLS apps. Only some versions have public fixes. Urgent upgrade warnings are out for all affected systems.
OpenSSL bug leaks unencrypted memory in DTLS connections Nerds Magazine © nerdsmagazine.com
OpenSSL bug leaks unencrypted memory in DTLS connections © nerdsmagazine.com

DTLS users who depend on OpenSSL for secure UDP traffic now face a serious security problem. A new bug, CVE-2026-84782, can leak unencrypted heap memory over a DTLS connection. It can also crash the app. This hits the heart of encrypted traffic.

OpenSSL rates the flaw as High. CISA gives it a score of 8.2 out of 10. This is not just a theory. If a DTLS handshake message stops mid-send and a resend starts, the protocol can send out heap memory fragments as plain handshake data. If the buffer read goes into unmapped memory, the app can crash. Both DTLS clients and servers are at risk. OpenSSL's own tests show this.

OpenSSL's patch set on September 29, 2026, addressed a total of 14 vulnerabilities, with CVE-2026-84782 identified as the most severe among them.

SecurityWeek

Laurent Gaffie from Secorizon reported the bug on August 17. Ryan Hooper wrote the fix. OpenSSL released patched versions-4.0.3, 3.6.5, 3.5.9, and 3.4.8-on September 29. But users on older branches like 3.0, 1.1.1, and 1.0.2 are stuck. Only those with premium support can get the fix. Public support for OpenSSL 3.0 ended September 7. The latest 3.0.23 release is now behind a paywall. Many open-source and enterprise systems are exposed unless they move to a newer branch.

DTLS secures WebRTC data channels and sets up encryption keys for internet calls. This bug is a real threat to live communications. The cause is simple. DTLS splits big handshake messages into UDP-sized chunks. If sending pauses, a resend timer can fire. Instead of sending the right message, the protocol may send leftover bytes from the buffer. This can leak sensitive heap data, unencrypted, to the other side.

The Debian Security Tracker says the root cause is a retransmission state bug in DTLS. If a handshake write is paused and a retransmission happens, the resend may use the wrong read spot. This can leak heap memory or crash the app. The fix resets the retransmission read position to the start of the message. It also skips retransmission while a handshake write is still paused.

The vulnerability is considered remotely exploitable over the network without authentication or user interaction, and is rated as high severity with a CVSS score of 8.2.

SecurityWeek

OpenSSL has not said if attackers can reliably trigger the resend bug. No attacks in the wild have been reported. Still, the project's security policy is blunt. Install updates with High-rated fixes right away. Ubuntu and Debian have already shipped patched packages. Ubuntu users must reboot for the fix to work. Debian 13 is patched. Debian 12 is still vulnerable as of September 30.

Stuck on OpenSSL 3.0? The risk is higher. The last public release, 3.0.22, does not have the fix. Only Ubuntu's packages for 22.04 and 24.04 LTS include the patch. Anyone building or bundling OpenSSL 3.0 from source has no public fix. OpenSSL's advice is simple. Upgrade to a supported branch like 4.0 or 3.5, or pay for premium support to get security fixes.

This update also fixes 13 other bugs. One is a Moderate-rated flaw (CVE-2026-84783) that can crash multi-threaded TLS clients or servers in rare certificate chain cases. Another is a Low-rated DTLS 1.2 bug (CVE-2026-75806) that lets a connection end with a single too-short datagram. The rest are Low, affecting QUIC code and cryptographic timing side-channels.

This OpenSSL crisis shows the risk for anyone slow to update or stuck on unsupported branches. The project now limits fixes for old versions to paying customers. That leaves much of the open-source world exposed. In this threat landscape, there are only two choices. Upgrade now, or accept the risk of running unpatched crypto software. Anything else is a gamble with secure communications.

Topics:
Cybersecurity Networking & Connectivity #Debian #Ubuntu #Security Updates
Ethan Cole Senior Technology Editor and PC troubleshooter Nerds Magazine
Senior Technology Editor

Ethan Cole

Ethan Cole is a Senior Technology Editor at NerdsMagazine covering Windows, PC hardware, troubleshooting, upgrades, gaming PCs, and system performance. His hands-on IT background shapes a diagnostic, reader-first approach that favors safe fixes, measurable improvements, and sensible upgrade decisions over hype or unnecessary replacement.