天下漏洞,尽知其名
MEDIUM

CVE-2026-75806 DTLS 1.2 拒绝服务漏洞

影响攻击者可发送单个未认证数据报终止已建立的 DTLS 1.2 关联,造成拒绝服务

AI 研判

该漏洞存在于 DTLS 1.2 记录层处理 AEAD 加密记录的过程中。当收到加密片段长度短于显式 IV 与认证标签开销的畸形记录时,记录层未先校验长度便将其交给密码实现,导致抛出致命 internal_error 告警并终止关联。攻击者无需掌握任何密钥材料即可触发。

影响范围

DTLS 1.2

影响使用 AEAD 密码套件的 DTLS 1.2 实现;具体受影响产品与版本范围暂无公开信息。

漏洞详情

漏洞类型为输入数量校验不当(CWE-1284)。在 TLS 1.2/DTLS 1.2 中,AEAD 保护的每条记录由显式 IV、密文和认证标签组成,解密前应先确认记录长度足以容纳 IV 与标签。实现却将记录长度直接传给密码实现,对过短记录返回的长度错误被当作内部故障处理,从而发送致命 internal_error 告警而非按认证失败处理,导致关联被拆除。

利用条件与风险

利用前提是攻击者能向已建立的 DTLS 1.2 关联发送数据报,无需密钥即可触发。影响限于目标关联的拒绝服务,不涉及内存安全或机密性,CVSS 5.3 属中危。

修复建议

官方修复方案暂无公开信息;建议关注相关实现的安全更新,及时升级到修复版本,并在边界限制不可信数据报的转发以降低触发面。

原始情报

Issue summary: An established DTLS 1.2 association using an AEAD cipher suite
can be terminated by a single unauthenticated datagram whose encrypted
fragment is shorter than the mandatory explicit IV and authentication tag
overhead.

Impact summary: An attacker who can send a datagram that is routed to an
existing DTLS 1.2 association can tear that association down without knowing
any key material. This is a Denial of Service limited to the targeted
association. There is no memory safety or confidentiality impact.

CWE: CWE-1284: Improper Validation of Specified Quantity in Input

Description: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher
suite carries an explicit IV followed by the ciphertext and an authentication
tag. When decrypting such a record the record layer passed the record length to
the cipher implementation before checking that the record was long enough to
contain the explicit IV and the tag. For a record shorter than that overhead the
cipher implementation rejected the impossible length, and the record layer
treated this as an internal failure and raised a fatal internal_error alert
instead of treating the record as one that failed authentication.

In TLS 1.2 the same record causes a fatal internal_error alert instead of the
expected bad_record_mac alert. Since any undecryptable record already
terminates a TLS connection, this is a protocol conformance issue rather than
a security issue in TLS.

The fix validates the record length against the explicit IV and tag length
before any AEAD processing, so that TLS reports bad_record_mac and DTLS
silently discards the record.

FIPS impact: no
The affected code is outside the FIPS module boundary.