OpenSSL has released fixes for a high-severity vulnerability in its DTLS implementation, tracked as CVE-2026-84782. The flaw can leak heap memory to the other side of a DTLS connection or crash the program. DTLS is the TLS variant used over UDP, commonly protecting WebRTC data channels and setting up encryption keys for internet calls.
The problem occurs during a handshake message resend. If a resend starts while a larger handshake message is only partially sent, the resent message uses the paused message's position in the buffer instead of going back to the start. This causes the resent message to carry the wrong label and leftover bytes from the larger message, which can overrun the buffer and expose unencrypted heap memory. OpenSSL says the flaw affects both DTLS clients and servers, but only if they use OpenSSL for DTLS.
Fixed versions are OpenSSL 4.0.3, 3.6.5, 3.5.9, and 3.4.8. Older branches—3.0, 1.1.1, and 1.0.2—receive fixes only for paying premium support customers; OpenSSL 3.0's public support ended on September 7. The project lists no workaround and has not reported any attacks exploiting the flaw, nor confirmed whether an attacker can trigger the vulnerable resend condition. CISA gave it a CVSS score of 8.2, rating confidentiality impact as low and availability as high.
Ubuntu and Debian have begun shipping their own updates for the affected OpenSSL versions. Ubuntu's advisory mentions possible incorrect handshake behavior or denial of service, but not the memory leak. OpenSSL recommends users on unsupported branches upgrade to a newer release, such as 4.0 or the long-term support branch 3.5.