freenode
Security & Cryptography

OpenSSL flags high-severity DTLS heap leak and crash risk

A flawed retransmission path can send leftover buffer bytes to a peer or abort the process when a handshake write is suspended mid-message.

OpenSSL has published a high-severity security advisory for CVE-2026-84782, a DTLS flaw that can disclose heap memory to a peer or crash the process.

DTLS may split a handshake message across several writes and pause mid-message when the transport cannot take more data. Independently, a retransmission timer can still fire and ask the stack to resend an earlier message. According to OpenSSL, the retransmission path reused the same buffer and position state as the suspended write instead of restarting at the beginning of the message being resent. The result is an out-of-bounds read: the peer can receive leftover bytes that were never meant to be sent as that handshake message, or the read can walk into unmapped memory and cause a denial of service.

Even a correctly positioned retransmit can corrupt the shared bookkeeping a suspended write needs. When the application later resumes via a normal SSL read, write, accept, or connect call, the inconsistent state can abort the process.

Tomas Mraz announced the issue for the project on 29 September 2026. The weakness is tracked as CWE-125 (out-of-bounds read) and matters for any deployment that speaks DTLS under load or lossy network conditions where partial writes and retransmits overlap.