Threat Intelligence

OpenSSL Patches High-Severity Bug That Could Leak Server Memory or Crash Programs

The Hacker News · 30 Sept 2026
Key Takeaway Australian businesses using applications built on OpenSSL for video calls, VoIP, or WebRTC should update to the latest patched version promptly to avoid memory leaks or service crashes.

OpenSSL has released fixes for a high-severity vulnerability, tracked as CVE-2026-84782, that affects DTLS, the encryption protocol used to protect UDP-based traffic such as WebRTC data channels and internet calls. The flaw involves how OpenSSL handles handshake message retransmissions. If a resend timer fires while a large handshake message is only partly sent, the retransmission can go out mislabeled, containing leftover bytes of server or client memory instead of the correct message. This can expose unencrypted heap memory to the other party in the connection, or cause the program to crash if it tries to read memory that isn't accessible.

The issue affects any software using OpenSSL for DTLS, in either client or server roles. It was reported by Laurent Gaffie of Secorizon and fixed by Ryan Hooper. Fixes are available in OpenSSL 4.0.3, 3.6.5, 3.5.9 and 3.4.8; older branches (3.0, 1.1.1, 1.0.2) only receive fixes through OpenSSL's paid premium support, and 3.0 no longer gets free public security updates as of September 7. OpenSSL has not confirmed whether attackers can deliberately trigger the vulnerable condition, and no active exploitation has been reported. CISA has rated the flaw 8.2 out of 10 in severity, noting low impact to confidentiality but high impact to availability.

OpenSSL rates the bug High, one step below Critical, and its policy recommends applying such fixes as soon as possible.

OpenSSL DTLS vulnerability patch management encryption

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.