OpenSSL Patches High-Severity DTLS Flaw That Can Expose Server Memory

Security camera undergoing privacy-mask persistence and configuration-drift testing

The OpenSSL project has fixed a high-severity vulnerability in its Datagram Transport Layer Security implementation that can disclose portions of server memory. CVE-2026-84782 affects applications using DTLS listening functionality and may expose data before a peer has been authenticated.

An invalid cookie could trigger an oversized response

According to the project advisory, a server processing a malformed ClientHello with an invalid cookie could calculate the length of its HelloVerifyRequest incorrectly. The resulting message could include uninitialized heap memory and transmit it without encryption. OpenSSL said the issue primarily affects DTLS servers built around BIO_s_datagram and DTLSv1_listen.

The project released corrected versions across supported branches, including OpenSSL 3.0.22, 3.3.7, 3.4.5, 3.5.5 and 3.6.1. Distribution advisories from Ubuntu and Debian provide package-level guidance for affected systems.

Operators need an application-level inventory

Teams should identify services that actually use DTLS server-listening functions, not assume every installed OpenSSL package has the same exposure. Internet-facing gateways, communications systems and embedded services deserve priority. After upgrading, operators should restart dependent processes and verify the loaded library version. SectechMedia follows related risks in its cybersecurity coverage.

Sources

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *