OpenSSL patches DTLS heap-disclosure flaw CVE-2026-84782
OpenSSL fixed CVE-2026-84782, a high-severity DTLS flaw that can leak unencrypted heap memory or crash DTLS apps; WolfSSL 5.9.4 separately patched three high-severity auth-bypass flaws.
OpenSSL shipped a security release on September 29 fixing CVE-2026-84782, a high-severity flaw in its DTLS retransmission path that can leak unencrypted heap memory to the peer or crash the application. The bug lands in the datagram TLS stack — the code path used by VPNs, VoIP, and IoT deployments that carry TLS over UDP.
The primary reference is the OpenSSL advisory 20260929.txt. The DTLS flaw was reported by Laurent Gaffie of secorizon.com.
What the bug does
Per the advisory, CVE-2026-84782 — "DTLS Retransmits Handshake Messages From a Stale Buffer Offset" — occurs when OpenSSL retransmits a DTLS handshake message while the send of a larger message is suspended. The retransmission mechanism mishandles the suspended write, reading past the allocated buffer. The result is either disclosure of heap memory as unencrypted handshake data to the other side, or a buffer overrun that crashes the process. SecurityWeek reports the flaw at CVSS 8.2.
Affected and fixed versions
- Affected: 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1, 1.0.2.
- Fixed: 4.0.3, 3.6.5, 3.5.9, 3.4.8. Premium-support-only backports: 3.0.23, 1.1.1zj, 1.0.2zs.
The same release rolls up roughly a dozen lower-severity issues, most in the QUIC stack (memory-allocation DoS conditions) and several constant-time/side-channel fixes in SM2 and non-NIST curve operations. CVE-2026-84782 is the only one rated High.
Exploitation status
None reported. OpenSSL has not stated whether an attacker can reliably force a retransmission while a message is stuck, and no in-the-wild exploitation is known.
Also this week: WolfSSL 5.9.4
Separately, WolfSSL 5.9.4 patched 11 vulnerabilities, including three high-severity flaws — CVE-2026-93302, CVE-2026-89102, and CVE-2026-89136 — that let an attacker bypass peer authentication by exploiting certificate-validation weaknesses in specific configurations, per SecurityWeek.
Action checklist
- Inventory DTLS users first. The heap-disclosure risk is on the DTLS path — prioritize VPN concentrators, VoIP/SIP media stacks, and embedded/IoT gear that negotiates DTLS.
- Upgrade to the fixed branch matching your deployment (4.0.3 / 3.6.5 / 3.5.9 / 3.4.8). If you run 3.0, 1.1.1, or 1.0.2, note the fixes are premium-support backports — plan the migration off end-of-mainstream branches.
- Rebuild and redeploy statically-linked binaries and containers that bundle OpenSSL; a host-level
opensslpackage bump won't cover them. - WolfSSL users: move to 5.9.4 and re-check any config that relies on custom certificate validation.
Context
DTLS retransmission bugs are a recurring class — the protocol's UDP retransmit logic has to juggle partial and out-of-order handshake state, and buffer-offset mistakes there tend to surface as memory disclosure rather than clean crashes. The mitigating factor is exposure: far fewer services speak DTLS than TLS, so the practical blast radius is narrower than the raw affected-version list suggests. Scope your response to the DTLS-speaking systems and this is a routine, if broad, patch cycle.