天下漏洞,尽知其名
HIGH 重点关注

CVE-2026-102712 DTLS ClientHello 解析越界读取漏洞

影响未认证攻击者可远程读取相邻进程内存并导致崩溃

AI 研判

该漏洞存在于 DTLS 协议栈对首个 ClientHello 报文的解析过程中。解析器直接采用设备声明的 session_id 长度,并在校验 ciphersuite 列表长度时使用整条记录长度而非剩余字节数,导致越界读取。读取到的相邻进程内存会被原样回显到 ServerHello 中,从而通过网络泄露。

影响范围

DTLS 协议实现

受影响的具体产品与版本范围暂无公开信息,涉及实现 DTLS 协议且存在该解析逻辑的组件。

漏洞详情

漏洞类型为越界读取(OOB Read)导致的信息泄露,成因是长度校验逻辑错误:ciphersuite 列表长度未与剩余字节数比较,而是与整条记录长度比较。未认证对端可构造首个 ClientHello 触发最多 255 字节的越界源读取,这些字节被原样写入返回的 ServerHello,从而泄露相邻进程内存;首个数据包即可触发崩溃变体。

利用条件与风险

利用无需认证,攻击者只需发送一个特制 DTLS ClientHello 数据包即可触发,实战中可造成内存信息泄露或服务崩溃,风险较高。

修复建议

官方修复方案暂无公开信息;建议在解析时严格按剩余字节数校验 ciphersuite 列表长度,并对 session_id 长度做边界检查,同时限制首个 ClientHello 的处理。临时缓解可考虑在边界设备过滤异常 DTLS 报文。

原始情报

On the first DTLS ClientHello, the parser copies a device-claimed session_id length and validates the

ciphersuite-list length against the total record length instead of the remaining bytes. An unauthenticated

peer drives an OOB source read of up to 255 bytes, and those bytes are echoed verbatim into the outgoing

ServerHello, disclosing adjacent process memory over the network. The crash variant fires on the first

packet.