CVE-2026-84782: 
Ruby Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-84782 is an out-of-bounds read vulnerability in OpenSSL's DTLS retransmission logic, formally titled "DTLS Retransmits Handshake Messages From a Stale Buffer Offset." It affects OpenSSL versions 1.0.2 before 1.0.2zs, 1.1.1 before 1.1.1zj, 3.0.x before 3.0.23, 3.4.x before 3.4.8, 3.5.x before 3.5.9, 3.6.x before 3.6.5, and 4.0.x before 4.0.3. The vulnerability was reported on September 18, 2026 and publicly disclosed on September 29, 2026. It carries a CVSS v3.1 base score of 8.2 (High) (Red Hat Advisory, Red Hat Bugzilla).

Détails techniques

The root cause is an out-of-bounds read (CWE-125) in the dtls1_retransmit_message() function within OpenSSL's DTLS handshake state machine. When a DTLS handshake message write is suspended mid-message due to a WANT_WRITE condition (e.g., the underlying BIO cannot accept more data), the internal buffer position tracker s->init_off retains the stale offset from the suspended write. If the DTLS retransmission timer fires during this suspended state, dtls1_do_write() resumes the retransmitted message from that stale offset rather than from the start of the message, producing a mislabeled fragment whose body contains arbitrary heap bytes from the larger in-flight message. The fix, applied in commits to ssl/statem/statem_dtls.c and ssl/d1_lib.c, resets s->init_off to 0 before each retransmission and adds a guard in dtls1_handle_timeout() to skip retransmission entirely when a write is still parked mid-flight (OpenSSL Commit 9f6b344, OpenSSL Commit 906cf0e).

Impact

Successful exploitation can result in two distinct outcomes: heap memory disclosure or denial of service. In the memory disclosure scenario, the retransmitted DTLS handshake fragment exposes arbitrary heap contents — potentially including sensitive cryptographic material or application data — to the remote peer as plaintext. In the denial of service scenario, the out-of-bounds read reaches an unmapped memory region, causing a process crash. The vulnerability is exploitable by unauthenticated network attackers against any service using OpenSSL's DTLS implementation, such as DTLS-based VPNs, WebRTC endpoints, or other UDP-based TLS services (Red Hat Advisory, Red Hat Bugzilla).

Exploitabilité

No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the disclosure date. The vulnerability is classified as automatable (no user interaction required) and exploitable by unauthenticated remote attackers, but requires the specific race condition of a suspended DTLS write coinciding with a retransmission timer event, which may limit practical exploitability. It is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The NVD SSVC assessment indicates no known exploitation (Red Hat Advisory).

Étapes d’exploitation

  1. Identify target: Locate services using OpenSSL's DTLS implementation (e.g., DTLS-based VPN gateways, WebRTC servers, or DTLS-enabled applications) running vulnerable OpenSSL versions prior to the patched releases.
  2. Initiate DTLS handshake: Connect to the target service over UDP and begin a DTLS handshake, triggering the exchange of large handshake messages (e.g., Certificate or ServerHello messages that span multiple fragments).
  3. Induce transport congestion: Throttle or congest the UDP path to the target so that the server's underlying BIO returns WANT_WRITE, suspending a large handshake message mid-write and leaving s->init_off at a non-zero offset.
  4. Wait for retransmission timer: Allow the DTLS retransmission timer to fire (typically after 1 second by default), triggering dtls1_handle_timeout() and subsequently dtls1_retransmit_message() while the write remains suspended.
  5. Receive leaked data: Capture the retransmitted DTLS fragment, which will contain heap memory bytes starting from the stale init_off offset rather than the intended message content — potentially disclosing sensitive heap data as plaintext handshake data.
  6. Trigger DoS (alternative): If the stale offset points beyond valid mapped memory, the out-of-bounds read causes a segmentation fault, crashing the OpenSSL process and achieving denial of service (OpenSSL Commit 9f6b344, Red Hat Advisory).

Indicateurs de compromis

  • Network: Malformed or anomalous DTLS handshake fragments received from a peer with inconsistent fragment offsets or lengths that do not correspond to expected message sizes; DTLS retransmission packets containing unexpected or garbled payload content.
  • Logs: Application or system logs showing repeated DTLS handshake failures, unexpected SSL/TLS errors during DTLS negotiation, or segmentation fault / crash reports in OpenSSL-linked services.
  • Process: Unexpected crashes (SIGSEGV) of DTLS-enabled services (e.g., VPN daemons, WebRTC servers) with stack traces referencing dtls1_retransmit_message(), dtls1_do_write(), or dtls1_handle_timeout() in OpenSSL libraries.
  • File System: Core dump files generated by DTLS-enabled service processes, potentially containing heap memory contents that could be analyzed for sensitive data exposure.

Atténuation et solutions de contournement

The primary remediation is to upgrade OpenSSL to a patched version: 1.0.2zs, 1.1.1zj, 3.0.23, 3.4.8, 3.5.9, 3.6.5, or 4.0.3 (or later). If immediate patching is not feasible, consider disabling DTLS where it is not operationally required, or restricting DTLS traffic at the network perimeter via firewall rules to limit exposure. Downstream distributions including Ubuntu (USN-8847-1, USN-8847-2) and FreeBSD (FreeBSD-SA-26:68.openssl) have also released updated packages (Red Hat Advisory, OpenSSL Release).

Réactions de la communauté

The vulnerability received broad coverage from security media outlets including The Hacker News, SecurityWeek, CyberSecurityNews, GBHackers, and Cryptika, with headlines emphasizing the heap memory leak aspect. Coverage noted that this was one of 14 security fixes included in the OpenSSL 4.0.3 release. FreeBSD issued a dedicated security advisory (FreeBSD-SA-26:68.openssl), and Ubuntu published two security notices (USN-8847-1 and USN-8847-2). Community discussion on Reddit's r/freebsd and Mastodon reflected routine patch-and-update sentiment without significant alarm, consistent with the absence of active exploitation (The Hacker News, SecurityWeek, FreeBSD Advisory).

Ressources additionnelles

État de correction de la distribution Linux

Disponibilité des correctifs sur les principales distributions Linux et leurs versions.

Debian

Fixe

bookworm

openssl

Affecté

sid

openssl: 3.6.5-1

Fixe

trixie

openssl: 3.5.7-1~deb13u3

Fixe

Ubuntu

Fixe

bionic (esm-apps)

nodejs

Inconnu

bionic (esm-infra)

openssl: 1.1.1-1ubuntu2.1~18.04.23+esm11

Fixe

bionic (fips-updates)

openssl

Inconnu

bionic (fips)

openssl

Inconnu

devel

openssl

Inconnu

focal (esm-apps)

nodejs

Non affecté

focal (esm-infra)

openssl: 1.1.1f-1ubuntu2.24+esm6

Fixe

focal (fips-updates)

openssl

Inconnu

RHEL / CentOS

Fixe

OpenShift

openshift/ose-rhel-coreos-8

Affecté

RHEL 8

389-ds:1.4/389-ds-base.src

Affecté

RHEL 9

:appstream:compat-openssl11/compat-openssl11-1:1.1.1k-5.el9_8.6

Fixe

RHEL 10

389-ds-base.src

Affecté

Alpine

Fixe

v3.21

openssl: 3.3.7-r2

Fixe

Source: Ce rapport a été généré à l’aide de l’IA

Apparenté Ruby Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-55107CRITICAL10
  • Ruby logoRuby
  • kobako
NonOuiSep 30, 2026
CVE-2026-77602CRITICAL9.9
  • Ruby logoRuby
  • openc3
NonOuiSep 23, 2026
CVE-2026-77601HIGH8.8
  • Ruby logoRuby
  • openc3
NonOuiSep 23, 2026
CVE-2026-84782HIGH8.2
  • Ruby logoRuby
  • rpm-sequoia-devel
NonOuiSep 29, 2026
GHSA-4825-p4xm-pcf2HIGH7.1
  • Ruby logoRuby
  • spree_api
NonOuiSep 22, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités