CVE-2026-84782
Received Received - Intake

DTLS Handshake Buffer Overread Leading to DoS

Vulnerability report for CVE-2026-84782, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: OpenSSL Software Foundation

Description

Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read past the message buffer and the retransmission overwrites the internal state the suspended write needs to resume correctly. Impact summary: The retransmitted message can disclose a heap memory to the peer as plaintext handshake data or cause a crash and a Denial of Service when the read reaches an unmapped memory region. CWE: CWE-125: Out-of-bounds Read Description: DTLS handshake messages can be written out in multiple fragments, and a write can suspend mid-message (returning WANT_WRITE) if the underlying transport temporarily cannot accept more data. While such a write is suspended, the DTLS retransmission timer may independently fire and ask the retransmission logic to resend an earlier, already-acknowledged-as-sent message from its retransmit queue. The retransmission logic reused the same internal buffer and position tracking as the message that was still being written, without resetting the position back to the start of the message being retransmitted. As a result the retransmission was read starting from wherever the suspended write had left off, producing a mislabelled message whose body was leftover bytes from the other, larger message still in flight - content that was never meant to be sent at that point, and which could run past the end of the allocated buffer. Separately, even when the retransmission is positioned correctly, allowing it to run to completion while another write is suspended overwrites the same shared bookkeeping that the suspended write depends on to resume. When the application later resumes the suspended write (via a subsequent SSL_read(), SSL_write(), SSL_accept(), or SSL_connect() call), it finds that bookkeeping in a state inconsistent with the message and aborts the process in a debugging build. The fix resets the retransmission's read position to the start of the message before resending, and skips retransmission entirely whenever a handshake write is still suspended, deferring to the next call that resumes it instead. FIPS impact: no The affected code is outside the FIPS module boundary.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
openssl openssl *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves a flaw in the DTLS retransmission logic where a suspended handshake message write is not handled correctly. When a retransmission occurs, it can read past the intended message buffer, exposing heap memory or causing a crash due to reading unmapped memory.

Detection Guidance

This vulnerability is specific to OpenSSL's DTLS implementation and requires code-level detection rather than network scanning. Check if your OpenSSL version is affected by verifying the version against patched releases. Use commands like 'openssl version' to check the installed version and compare it with the fixed versions mentioned in the patches.

Impact Analysis

The vulnerability can lead to two main issues: disclosure of sensitive heap memory to peers as plaintext handshake data or a Denial of Service (DoS) attack if the read reaches unmapped memory, causing a crash.

Compliance Impact

This vulnerability could potentially affect compliance with GDPR and HIPAA by exposing sensitive data through out-of-bounds memory reads during DTLS retransmissions. The flaw allows heap memory disclosure as plaintext handshake data, which may include personal or protected health information if transmitted over DTLS. This could violate GDPR's data protection principles or HIPAA's security requirements for safeguarding protected health information.

Mitigation Strategies

Update OpenSSL to the latest patched version to address the DTLS retransmission logic flaw. Disable DTLS if not required. Monitor network traffic for unusual handshake patterns or crashes during SSL/TLS operations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84782. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart