CVE-2026-75806: falha de média gravidade em OpenSSL
Unauthenticated and Undersized DTLS 1.2 AEAD Record Causes DoS
Publicada em
13Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 5.3epss 0.4%
probabilidade de exploração
0.4%top 69% das CVEs
exploração observada
nãonenhuma fonte reporta
Issue summary: An established DTLS 1.2 association using an AEAD cipher suite
can be terminated by a single unauthenticated datagram whose encrypted
fragment is shorter than the mandatory explicit IV and authentication tag
overhead.
Impact summary: An attacker who can send a datagram that is routed to an
existing DTLS 1.2 association can tear that association down without knowing
any key material. This is a Denial of Service limited to the targeted
association. There is no memory safety or confidentiality impact.
CWE: CWE-1284: Improper Validation of Specified Quantity in Input
Description: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher
suite carries an explicit IV followed by the ciphertext and an authentication
tag. When decrypting such a record the record layer passed the record length to
the cipher implementation before checking that the record was long enough to
contain the explicit IV and the tag. For a record shorter than that overhead the
cipher implementation rejected the impossible length, and the record layer
treated this as an internal failure and raised a fatal internal_error alert
instead of treating the record as one that failed authentication.
In TLS 1.2 the same record causes a fatal internal_error alert instead of the
expected bad_record_mac alert. Since any undecryptable record already
terminates a TLS connection, this is a protocol conformance issue rather than
a security issue in TLS.
The fix validates the record length against the explicit IV and tag length
before any AEAD processing, so that TLS reports bad_record_mac and DTLS
silently discards the record.
FIPS impact: no
The affected code is outside the FIPS module boundary.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Produtos afetados
OpenSSL · OpenSSLCVEs relacionadas — OpenSSL
No mesmo produto, das mais perigosas para as menos.
CVE-2022-2068CRITICALThe c_rehash script allows command injectionEPSS 95.4%CVE-2022-3786HIGHX.509 Email Address Variable Length Buffer OverflowEPSS 92.5%CVE-2022-3602HIGHX.509 Email Address 4-byte Buffer OverflowEPSS 90.8%CVE-2021-3711—SM2 Decryption Buffer OverflowEPSS 87.8%CVE-2022-1292CRITICALThe c_rehash script allows command injectionEPSS 82.6%CVE-2023-2650MEDIUMPossible DoS translating ASN.1 object identifiersEPSS 75.1%
Referências
https://github.com/openssl/openssl/commit/04728a289a823e68137f88da016cb9ede307217dhttps://github.com/openssl/openssl/commit/050b275cd671a6eed1d6457642d41a5a77aab972https://github.com/openssl/openssl/commit/3a4589d015a9049d47b66f186cf50a8711343a1dhttps://github.com/openssl/openssl/commit/5af82fefbaf2b5fec2fc0e1d87f112844902f01dhttps://openssl-library.org/news/secadv/20260929.txt