Skip to content
TrustList
News

OpenSSL security release of 29 September 2026 fixes a high-severity DTLS flaw, CVE-2026-84782, and a use-after-free

Editorial

By TrustList Editorial

OpenSSL published fixes on 29 September 2026, led by high-severity CVE-2026-84782, where DTLS retransmits handshake messages from a stale buffer offset, and a moderate use-after-free. Fixed in 4.0.3, 3.6.5, 3.5.9, 3.4.8 and 3.0.23.

About OpenSSL security release of 29 September 2026 fixes a high-severity DTLS flaw, CVE-2026-84782, and a use-after-free

OpenSSL security release of 29 September 2026 fixes a high-severity DTLS flaw, CVE-2026-84782, and a use-after-free

29 September 2026 — The OpenSSL project published a set of vulnerability fixes on 29 September 2026. OpenSSL is the cryptography library behind TLS in a large share of servers, appliances and applications. The release is led by one high-severity issue and one moderate one; the rest are rated low.

The two most serious issues

  • CVE-2026-84782 (High): "DTLS Retransmits Handshake Messages From a Stale Buffer Offset". It affects DTLS, the datagram version of TLS used by VPNs, VoIP, WebRTC and some IoT protocols. It was found by Laurent Gaffie and fixed by Ryan Hooper. Affected versions: 4.0.0 before 4.0.3, 3.6.0 before 3.6.5, 3.5.0 before 3.5.9, and further lines listed on the advisory.
  • CVE-2026-84783 (Moderate): "Use-After-Free in X.509 Extension Cache Under Concurrent Use". It affects certificate handling in multi-threaded programs, and was found by Tim Becker (Xint.io) and aydinmercan.

The project's list for the same date also includes a series of low-severity fixes: QUIC denial-of-service issues, timing side channels in ECDSA and SM2, and excessive memory allocation from crafted certificates. For that last one, the advisory lists every affected line: 4.0 before 4.0.3, 3.6 before 3.6.5, 3.5 before 3.5.9, 3.4 before 3.4.8, 3.0 before 3.0.23, and the premium-support 1.1.1 and 1.0.2 lines.

Who is affected

OpenSSL is linked into operating systems, language runtimes, web servers, network appliances and many commercial applications, often as a bundled copy. The high-severity flaw matters only where DTLS is in use. Anything that parses certificates in several threads at once is exposed to the use-after-free. The project has not reported exploitation of any of these issues.

What to do

  • Update to OpenSSL 4.0.3, 3.6.5, 3.5.9, 3.4.8 or 3.0.23, whichever matches your line, or take your operating-system vendor's patched package when it ships.
  • Software vendors that bundle OpenSSL should ship an update to customers, and state which OpenSSL version it contains.
  • Prioritise products that use DTLS (VPN gateways, VoIP and real-time media servers, IoT gateways).
  • Buyers should ask their appliance and software suppliers when a fixed build will be available.

Sources

Categories & features