Find notable cyber news and cases, enriched with sources, timelines, and signals.

OpenSSL DTLS memory leak or crash flaw (CVE-2026-84782)

Vulnerability
First reported
Last updated
Happening score
H score 24
1 unique sources, 1 articles

Summary

Hide ▲

CVE-2026-84782 affects OpenSSL DTLS and can leak heap memory to the peer or crash affected programs. OpenSSL has released fixes in 4.0.3, 3.6.5, 3.5.9 and 3.4.8, with older branches limited to premium-support customers. The flaw is high severity and has no reported exploitation so far.

Related Happenings

Linux kernel Dirty Frag local root escalation privilege-escalation flaw

Vulnerability
H score30 First: 08.05.2026 10:45 Last: 08.05.2026 10:45 Sources 1

About this happening: Dirty Frag is a newly disclosed Linux kernel zero-day that can give local attackers root privileges on most major Linux distributions. The flaw is anchored in the...

Timeline

  1. 30.09.2026 11:09 1 articles · 4h ago

    Secorizon researcher reports CVE-2026-84782 to OpenSSL

    Initial Disclosure

    Laurent Gaffie of Secorizon reported CVE-2026-84782 to OpenSSL on August 17 after identifying a DTLS flaw that can leak heap memory to the other side of a DTLS connection or crash affected programs.

    Show sources
  2. 30.09.2026 11:09 2 articles · 4h ago

    OpenSSL releases fixes for CVE-2026-84782

    Mitigation Patch Update

    OpenSSL released fixes for CVE-2026-84782 on September 29, shipping OpenSSL 4.0.3, 3.6.5, 3.5.9 and 3.4.8 for a DTLS resend flaw that can expose heap memory as unencrypted handshake data or crash the program; CISA rated the issue 8.2/10 and listed exploitation as none.

    Show sources
  3. 30.09.2026 11:09 1 articles · 4h ago

    Ubuntu ships package updates for CVE-2026-84782

    Mitigation Patch Update

    Ubuntu fixed CVE-2026-84782 on September 29 in its own packages, publishing updated libssl3t64 and libssl3 builds for Ubuntu 26.04 LTS, 24.04 LTS and 22.04 LTS, and users need to reboot for all changes to take effect.

    Show sources
  4. 30.09.2026 11:09 1 articles · 4h ago

    Debian 12 remains listed as vulnerable to CVE-2026-84782

    Victim Impact Update

    Debian's security tracker still listed Debian 12 as vulnerable as of 07:36 UTC on September 30, showing that the affected release had not yet been cleared from the tracker at that time.

    Show sources