OpenSSL DTLS Memory Leak: Unpacking CVE-2026-84782
A malfunction within the DTLS retransmission mechanism transformed the routine recovery of a lost message into a critical memory leak. The architects of OpenSSL have formally disclosed vulnerability CVE-2026-84782, assigning it a severe CVSS 3.1 score of 8.2.
DTLS safeguards data exchange over UDP and must inherently possess the capability to retransmit handshake messages should a response vanish. The flaw materialized when the transmission of a voluminous message paused mid-stream, concurrently triggering a timer that initiated the retransmission of a preceding message. Instead of reading from the buffer’s inception, OpenSSL erroneously continued reading from the precise location where the prior write operation had halted.
The Mechanics of the Out-of-Bounds Read
Consequently, due to this inaccurate offset, the retransmission could improperly capture extraneous bytes from the process memory, transmitting them to the remote peer as unencrypted handshake data. Should the read operation extend into an unmapped memory region, the application would catastrophically crash, thereby mutating the flaw into a denial-of-service condition. This vulnerability is technically classified as an out-of-bounds read, designated as CWE-125.
The issue pervades OpenSSL versions 4.0 through 4.0.3, 3.6 through 3.6.5, 3.5 through 3.5.9, and 3.4 through 3.4.8. Furthermore, the legacy 3.0, 1.1.1, and 1.0.2 branches remain susceptible. Remediated builds for these legacy iterations carry the designations 3.0.23, 1.1.1zj, and 1.0.2zs; however, public support for these branches has formally concluded or operates strictly under extended support provisions.
Logic Adjustments and Mitigation
The implemented patch rectifies two fundamental aspects of the logic. Prior to any retransmission, OpenSSL now definitively resets the read position to the message’s origin; furthermore, in instances of incomplete writes, it postpones the retry entirely until a subsequent call resumes the handshake sequence. By enforcing these protocols, the library ceases to utilize a singular internal context simultaneously for two fundamentally incompatible operations.
Executing this scenario demands a precise confluence of DTLS, non-blocking I/O operations, and a specific moment when the handshake write process is already suspended. Therefore, this defect does not invariably guarantee an automatic memory leak across every active connection. Red Hat evaluated this identical CVE with a CVSS 3.1 score of 7.4, assessing the attack complexity as exceptionally high, whereas the official CVE repository employs a more stringent rating of 8.2.
During the preceding summer, researchers discovered a distinct memory-related anomaly within OpenSSL dubbed HollowByte, wherein a truncated request compelled the server to reserve an egregiously disproportionate volume of memory during the TLS handshake. This novel CVE pertains to a completely separate mechanism and is exclusive to DTLS. Fortunately, the vulnerable code resides entirely outside the boundaries of the FIPS module; consequently, certified FIPS components remain directly unaffected.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.