OpenSSL releases fixes for High-severity DTLS memory disclosure flaw

OpenSSL has released fixes for CVE-2026-84782, a High-severity defect in DTLS that can disclose heap memory in unencrypted handshake data to the peer or crash an affected program. The public updates are OpenSSL 4.0.3, 3.6.5, 3.5.9 and 3.4.8.
The issue affects software that uses OpenSSL for DTLS, the UDP-oriented variant of TLS. OpenSSL said it has not established whether an attacker can force the retransmission condition, and it had reported no exploitation at the time of disclosure.
How the DTLS retransmission error occurs
DTLS retransmits handshake messages when a reply does not arrive before its timer expires. Large handshake messages are split into fragments that fit inside UDP datagrams, and transmission can pause if the connection is temporarily unable to accept more data.
The flaw can arise when that pause occurs in the middle of a large handshake message and the retransmission timer fires. Before the fix, the retransmission used the buffer position of the paused message rather than returning to the start of the message being resent.
As a result, the resent record can be assigned the wrong message label and contain residual bytes from the larger handshake message. OpenSSL said those bytes may expose heap memory as unencrypted handshake data. A read beyond the buffer can instead reach unmapped memory and terminate the process.
Versions, support status and distribution updates
OpenSSL rates CVE-2026-84782 as High, one level below Critical in its own scale. CISA assigned it a CVSS score of 8.2 out of 10, with Low confidentiality impact and High availability impact. OpenSSL does not use CVSS for its own severity ratings and notes that external scores can differ substantially.
The affected branches are 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 in releases preceding their respective fixes. Fixes for 3.0, 1.1.1 and 1.0.2 are available only to premium support customers: 3.0.23, 1.1.1zj and 1.0.2zs. Public security support for OpenSSL 3.0 ended on September 7, 2026.
OpenSSL listed no workaround for organizations unable to update. It recommends moving OpenSSL 3.0 deployments to a newer branch such as 4.0 or the long-term support 3.5 release, or obtaining paid support for end-of-public-support versions.
Ubuntu and Debian package status
Ubuntu issued fixes on September 29 in packages that retain distribution-specific version numbers: libssl3t64 3.5.5-1ubuntu3.6 for Ubuntu 26.04 LTS, libssl3t64 3.0.13-0ubuntu3.16 for Ubuntu 24.04 LTS, and libssl3 3.0.2-0ubuntu1.30 for Ubuntu 22.04 LTS. Ubuntu requires a reboot after updating for all changes to take effect.
Debian fixed the issue in Debian 13 through openssl 3.5.7-1~deb13u3, released as DSA-6531-1. Its tracker still listed Debian 12 as vulnerable on September 30.
Operational priority
Security teams should identify services that use OpenSSL-backed DTLS, including deployments supporting WebRTC data channels or internet-call key establishment, verify the package or embedded library version, and apply the applicable vendor update. Organizations maintaining their own OpenSSL 3.0 builds need to plan an upgrade or support path because OpenSSL no longer provides a public fix for that branch.

