PT-2026-81301 · Openssl+3 · Openssl+3
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
OpenSSL versions 1.0.2 through 4.0
Description
Receiving a DTLS record for a future epoch during a handshake causes the system to buffer significantly more memory than the record requires. This occurs because the software retains the entire read buffer, sized for the largest possible DTLS record (approximately 16 kilobytes), instead of only the actual record bytes. Since up to 100 records can be buffered per connection, an attacker can send small forged records to force the endpoint to retain about 1.7 megabytes of memory per connection. This memory amplification can lead to remote memory exhaustion and a Denial of Service for DTLS servers.
Recommendations
Upgrade OpenSSL version 4.0 to 4.0.2
Upgrade OpenSSL version 3.6 to 3.6.4
Upgrade OpenSSL version 3.5 to 3.5.8
Upgrade OpenSSL version 3.4 to 3.4.7
Upgrade OpenSSL version 3.0 to 3.0.22
Upgrade OpenSSL version 1.1.1 to 1.1.1zi
Upgrade OpenSSL version 1.0.2 to 1.0.2zr
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freebsd
Linuxmint
Openssl
Ubuntu