CVE-2026-75806
Received Received - Intake

DTLS 1.2 Association Termination via Short Encrypted Datagram

Vulnerability report for CVE-2026-75806, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: OpenSSL Software Foundation

Description

Issue summary: An established DTLS 1.2 association using an AEAD cipher suite can be terminated by a single unauthenticated datagram whose encrypted fragment is shorter than the mandatory explicit IV and authentication tag overhead. Impact summary: An attacker who can send a datagram that is routed to an existing DTLS 1.2 association can tear that association down without knowing any key material. This is a Denial of Service limited to the targeted association. There is no memory safety or confidentiality impact. CWE: CWE-1284: Improper Validation of Specified Quantity in Input Description: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher suite carries an explicit IV followed by the ciphertext and an authentication tag. When decrypting such a record the record layer passed the record length to the cipher implementation before checking that the record was long enough to contain the explicit IV and the tag. For a record shorter than that overhead the cipher implementation rejected the impossible length, and the record layer treated this as an internal failure and raised a fatal internal_error alert instead of treating the record as one that failed authentication. In TLS 1.2 the same record causes a fatal internal_error alert instead of the expected bad_record_mac alert. Since any undecryptable record already terminates a TLS connection, this is a protocol conformance issue rather than a security issue in TLS. The fix validates the record length against the explicit IV and tag length before any AEAD processing, so that TLS reports bad_record_mac and DTLS silently discards the record. FIPS impact: no The affected code is outside the FIPS module boundary.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
openssl openssl *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1284 The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves DTLS 1.2 associations using AEAD cipher suites. An attacker can send a single unauthenticated datagram with an encrypted fragment shorter than the required explicit IV and authentication tag. This causes the association to terminate without needing any key material, resulting in a Denial of Service limited to the targeted connection. No memory safety or confidentiality impact occurs.

Detection Guidance

Detecting this vulnerability requires monitoring for malformed TLS/DTLS AEAD records. Use network monitoring tools like Wireshark to inspect TLS/DTLS traffic for records shorter than the required explicit IV and authentication tag length. Check OpenSSL logs for SSL_AD_INTERNAL_ERROR alerts which may indicate exploitation attempts.

Impact Analysis

The impact is a Denial of Service where an attacker can terminate an existing DTLS 1.2 association by sending a malformed datagram. This disrupts the targeted connection but does not compromise data confidentiality or integrity.

Mitigation Strategies

Update OpenSSL to the latest patched version that includes the fix for CVE-2026-75806. If immediate patching is not possible, disable TLS 1.2 AEAD cipher suites temporarily as a workaround. Monitor network traffic for signs of exploitation attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-75806. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart