CVE-2026-84782
CVSS 8.2 HIGH: issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended…
Vulnerabilità ed exploit
OpenSSL e WolfSSL hanno rilasciato patch per circa una dozzina di falle ciascuna. Sul fronte OpenSSL, CVE-2026-84782 è la più rilevante: una falla ad alta gravità nel retransmission di DTLS può esporre frammenti di heap oppure mandare in crash i servizi che usano quella modalità.
Il problema scatta durante il handshake DTLS. Se un invio si blocca a metà, il retry può riprendere dal punto sbagliato e rimandare byte rimasti in memoria al posto del solo messaggio previsto. Il risultato è un leak di dati in chiaro sulla sessione, o un DoS se la lettura arriva a memoria non mappata. CVE-2026-84783 corregge anche un altro crash in client TLS multi-threaded.
Per chi usa OpenSSL o WolfSSL in VPN, VoIP, WebRTC o IoT, l’esposizione riguarda la libreria incorporata, non solo il prodotto visibile a valle. Sulle vecchie linee OpenSSL, le correzioni per alcuni rami possono passare solo dal supporto a pagamento, quindi non tutti gli ambienti legacy hanno lo stesso percorso di patch.
3 fonti · 6 ore fa
CVSS 8.2 HIGH: issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended…
CVSS 7.5 HIGH: issue summary: The first concurrent use of the same X.509 certificate by several threads may cause its cached…
CSIRT Italia / ACN
Risolte vulnerabilità in OpenSSL
Rilasciati aggiornamenti di sicurezza che sanano 14 vulnerabilità, di cui 4 con gravità "alta", in OpenSSL, software open source per la gestione delle comunicazioni crittografiche.
originaleThe Hacker News
OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted
OpenSSL fixed a DTLS flaw rated High that can leak heap memory or crash software using OpenSSL for DTLS; no attacks are reported.
originaleSecurityWeek
High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL
Roughly a dozen vulnerabilities have been patched in each of the open source cryptographic libraries.
originalePart of the PlainSec briefing for 2026-09-30
Every edition of this story: OpenSSL espone memoria nei handshake DTLS