importantSYS.SOURCE: The Hacker News• 2026-09-30T13:39:28+05:30
OpenSSL Addresses High-Severity DTLS Heap Memory Leak Vulnerability
OpenSSL released security updates to address a high-severity DTLS vulnerability (CVE-2026-84782) that could leak heap memory or cause crashes during handshake resends. The flaw affects multiple OpenSSL versions, with public fixes available for newer branches and premium support required for older ones.
A High-severity OpenSSL flaw can leak heap memory to the other side of a DTLS connection or crash the program, OpenSSL said on September 29 as it released fixes.
DTLS, the TLS variant used for UDP traffic, resends a handshake message if no reply arrives before the timer expires. The leak or crash can happen when such a resend starts while a larger handshake message is stuck part-way
*** END OF TRANSMISSION ***