Leftover server memory can cross a DTLS connection in the clear. OpenSSL patched that flaw on September 29 and rated it high severity, warning it can also crash the process.
DTLS is the UDP-flavoured cousin of TLS that WebRTC data channels and internet calling depend on. Big handshake messages get chopped into datagrams, and if a reply stalls, the sender retries after a timer. The bug surfaces when that retry lands while a larger message sits half-sent: instead of restarting, the code reused the paused buffer position, so the retried packet carried the wrong label and leftover bytes as its payload.
The mislabelled packet drags heap contents to the far end as plaintext handshake data, and a read that strays into unmapped memory trips a crash, OpenSSL said. Both the client and server roles are exposed.
Tracked as CVE-2026-84782, the flaw is corrected in 4.0.3, 3.6.5, 3.5.9 and 3.4.8. Anyone on the 3.0, 1.1.1 or 1.0.2 lines will not find a free download, since those fixes sit behind a paid support contract; free security updates for the 3.0 branch ended September 7. No attackers are known to have used the bug, which CISA scores 8.2. Ubuntu and Debian pushed their own packages.
