天下漏洞,尽知其名
HIGH

CVE-2026-84782 OpenSSL DTLS 越界读取漏洞

影响可泄露堆内存明文数据或导致进程崩溃拒绝服务

AI 研判

OpenSSL 的 DTLS 重传逻辑在处理被中途挂起(返回 WANT_WRITE)的握手消息写入时存在缺陷。当重传定时器在写入挂起期间触发,重传逻辑复用了同一内部缓冲区与位置跟踪,却未将读取位置重置到待重传消息的起始处,导致越界读取。该问题被归类为 CWE-125 越界读取,CVSS 评分 8.2(HIGH)。

影响范围

OpenSSL

受影响的具体 OpenSSL 版本范围暂无公开信息,需以官方安全公告为准。

漏洞详情

DTLS 握手消息可分片写出,若底层传输暂时无法接收更多数据,写入会中途挂起并返回 WANT_WRITE。此时重传定时器可能独立触发,要求重传队列中一条更早、已确认发送的消息。重传逻辑复用了仍在写入中的消息所用的内部缓冲区和位置跟踪,未将位置重置回待重传消息的开头,导致从错误偏移读取,越过消息缓冲区边界,并覆盖挂起写入恢复所需的内部状态。后果是可能将堆内存作为明文握手数据泄露给对端,或读取到未映射内存区域导致崩溃和拒绝服务。

利用条件与风险

利用前提是使用 DTLS 且出现写入挂起并伴随重传定时器触发的场景,攻击者需能与目标建立 DTLS 连接。实战中可造成堆内存信息泄露或服务崩溃,风险较高。

修复建议

官方修复方案暂无公开信息,建议关注 OpenSSL 官方安全公告并及时升级到修复版本;临时缓解可考虑在受影响环境中限制或关闭 DTLS 服务,或降低暴露面。

原始情报

Issue summary: The DTLS retransmission logic does not correctly handle
a handshake message write that is suspended part-way through.
The retransmitted message can be read past the message buffer and
the retransmission overwrites the internal state the suspended write
needs to resume correctly.

Impact summary: The retransmitted message can disclose a heap memory
to the peer as plaintext handshake data or cause a crash and a Denial
of Service when the read reaches an unmapped memory region.

CWE: CWE-125: Out-of-bounds Read

Description: DTLS handshake messages can be written out in multiple
fragments, and a write can suspend mid-message (returning WANT_WRITE)
if the underlying transport temporarily cannot accept more data. While
such a write is suspended, the DTLS retransmission timer may
independently fire and ask the retransmission logic to resend an
earlier, already-acknowledged-as-sent message from its retransmit
queue.

The retransmission logic reused the same internal buffer and position
tracking as the message that was still being written, without
resetting the position back to the start of the message being
retransmitted. As a result the retransmission was read starting from
wherever the suspended write had left off, producing a mislabelled
message whose body was leftover bytes from the other, larger message
still in flight – content that was never meant to be sent at that
point, and which could run past the end of the allocated buffer.

Separately, even when the retransmission is positioned correctly,
allowing it to run to completion while another write is suspended
overwrites the same shared bookkeeping that the suspended write
depends on to resume. When the application later resumes the
suspended write (via a subsequent SSL_read(), SSL_write(),
SSL_accept(), or SSL_connect() call), it finds that bookkeeping in a
state inconsistent with the message and aborts the process in
a debugging build.

The fix resets the retransmission’s read position to the start of the
message before resending, and skips retransmission entirely whenever a
handshake write is still suspended, deferring to the next call that
resumes it instead.

FIPS impact: no
The affected code is outside the FIPS module boundary.