OpenSSL 29 Sep advisory: High CVE-2026-84782 DTLS stale-buffer retransmit (heap leak/DoS) + Moderate CVE-2026-84783 X.509 cache UAF; 12 Low; fix 4.0.3 / 3.6.5 / 3.5.9 / 3.4.8
OpenSSL Security Advisory (29 September 2026) patches 14 vulnerabilities. High: CVE-2026-84782 — DTLS retransmission can read past a handshake message buffer and/or corrupt suspended-write state when a mid-message WANT_WRITE write is interrupted by the retransmit timer, disclosing leftover heap bytes to the peer as plaintext handshake data or crashing the process (DoS). Affects OpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2. Moderate: CVE-2026-84783 — use-after-free in X.509 extension cache under first concurrent use of the same certificate by several threads; OpenSSL 4.0 only (multi-threaded TLS client, or server that requests client certs). Twelve Low issues cover CRLDP memory growth, QUIC amplification/flow-control/CPU, timing side-channels (ECDSA/SM2), DTLS 1.2 tear-down, CMP NULL deref, and related. OpenSSL rates severity High/Moderate/Low; no numeric CVSS in the vendor advisory (desk does not invent scores). Distinct from wolfSSL 5.9.4 (wolfssl-5-9-4-20260928); SecurityWeek 30 Sep roundup covers both libraries. Primary: OpenSSL secadv 20260929; wire: SecurityWeek 30 Sep.
- Product
- OpenSSL (DTLS / TLS / QUIC / X.509)
- Versions
- CVE-2026-84782 affected: OpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1, 1.0.2. CVE-2026-84783 affected: OpenSSL 4.0 only. Fixed: 4.0.3, 3.6.5, 3.5.9, 3.4.8; premium-support lines 3.0.23 / 1.1.1zj / 1.0.2zs. Low issues share the same public fixed releases where applicable.
- Exploited in Australia?
- unknown
- Patch to
- Upgrade OpenSSL to 4.0.3 / 3.6.5 / 3.5.9 / 3.4.8 (or premium 3.0.23 / 1.1.1zj / 1.0.2zs) per your branch. Prioritise DTLS-facing VPN/VoIP/IoT and any OpenSSL 4.0 multi-threaded TLS clients/servers that verify peer certificates. Rebuild/relink dependent packages; confirm runtime library version after deploy. No evidence of in-the-wild exploitation cited in the advisory.
Primary: OpenSSL — Security Advisory 29 September 2026 · Vendor: OpenSSL — security advisory index · CVE: CVE-2026-84782, CVE-2026-84783 · SecurityWeek — OpenSSL + wolfSSL high-severity patches (30 Sep 2026)
