OpenSSL DTLS memory leak or crash flaw (CVE-2026-84782)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2026-84782 affects OpenSSL DTLS and can leak heap memory to the peer or crash affected programs. OpenSSL has released fixes in 4.0.3, 3.6.5, 3.5.9 and 3.4.8, with older branches limited to premium-support customers. The flaw is high severity and has no reported exploitation so far.
Related Happenings
Linux kernel Dirty Frag local root escalation privilege-escalation flaw
Vulnerability
H score30
First: 08.05.2026 10:45
Last: 08.05.2026 10:45
Sources 1
About this happening:
Dirty Frag is a newly disclosed Linux kernel zero-day that can give local attackers root privileges on most major Linux distributions. The flaw is anchored in the...
Linux kernel Dirty Frag local root escalation privilege-escalation flaw
VulnerabilityAbout this happening: Dirty Frag is a newly disclosed Linux kernel zero-day that can give local attackers root privileges on most major Linux distributions. The flaw is anchored in the...
Timeline
-
30.09.2026 11:09 1 articles · 4h ago
Secorizon researcher reports CVE-2026-84782 to OpenSSL
Initial DisclosureLaurent Gaffie of Secorizon reported CVE-2026-84782 to OpenSSL on August 17 after identifying a DTLS flaw that can leak heap memory to the other side of a DTLS connection or crash affected programs.
Show sources
- OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted — thehackernews.com — 30.09.2026 11:09
-
30.09.2026 11:09 2 articles · 4h ago
OpenSSL releases fixes for CVE-2026-84782
Mitigation Patch UpdateOpenSSL released fixes for CVE-2026-84782 on September 29, shipping OpenSSL 4.0.3, 3.6.5, 3.5.9 and 3.4.8 for a DTLS resend flaw that can expose heap memory as unencrypted handshake data or crash the program; CISA rated the issue 8.2/10 and listed exploitation as none.
Show sources
- OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted — thehackernews.com — 30.09.2026 11:09
- OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted — thehackernews.com — 30.09.2026 11:09
-
30.09.2026 11:09 1 articles · 4h ago
Ubuntu ships package updates for CVE-2026-84782
Mitigation Patch UpdateUbuntu fixed CVE-2026-84782 on September 29 in its own packages, publishing updated libssl3t64 and libssl3 builds for Ubuntu 26.04 LTS, 24.04 LTS and 22.04 LTS, and users need to reboot for all changes to take effect.
Show sources
- OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted — thehackernews.com — 30.09.2026 11:09
-
30.09.2026 11:09 1 articles · 4h ago
Debian 12 remains listed as vulnerable to CVE-2026-84782
Victim Impact UpdateDebian's security tracker still listed Debian 12 as vulnerable as of 07:36 UTC on September 30, showing that the affected release had not yet been cleared from the tracker at that time.
Show sources
- OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted — thehackernews.com — 30.09.2026 11:09