OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted
Sep 30, 2026
Vulnerability / Network Security
A High-severity OpenSSL flaw can leak heap memory to the other side of a DTLS connection or crash the program, OpenSSL said on September 29 as it released fixes. DTLS , the TLS variant used for UDP traffic, resends a handshake message if no reply arrives before the timer expires. The leak or crash can happen when such a resend starts while a larger handshake message is stuck part-way through being sent. The flaw, tracked as CVE-2026-84782, is fixed in OpenSSL 4.0.3, 3.6.5, 3.5.9 and 3.4.8 . Fixed versions for the older 3.0, 1.1.1 and 1.0.2 branches go only to customers who pay for OpenSSL's premium support. OpenSSL 3.0 stopped getting public security fixes on September 7. OpenSSL has not said whether an attacker can cause a resend while a message is stuck, nor has it reported any attacks exploiting the flaw. DTLS is used, for example, to protect WebRTC data channels and to set up encryption keys for internet calls. Software is exposed to this fla...