By Interestana AI Editorial — AI-drafted, human-overseen. How we report
OpenSSL Patches High-Severity DTLS Heap Memory Leak

OpenSSL released fixes on September 29 for a high-severity vulnerability affecting its Datagram Transport Layer Security (DTLS) implementation, which could lead to the unencrypted leakage of heap memory or program crashes. The vulnerability, identified as CVE-2023-56794, specifically impacts the DTLS handshake process when using UDP traffic. DTLS is a variant of the Transport Layer Security (TLS) protocol designed to provide security for datagram protocols, most notably User Datagram Protocol (UDP).
The flaw can be triggered when a DTLS handshake message is retransmitted due to a timer expiring before a reply is received, while a larger handshake message is in the process of being sent and becomes stuck part-way. This specific timing condition allows an attacker to potentially intercept sensitive data residing in the application's heap memory. The heap is a region of a computer's memory that is managed by the operating system and is used for dynamic memory allocation, meaning it holds data whose size is not known until runtime. Leaking this memory can expose sensitive information such as cryptographic keys, user credentials, or other private data.
OpenSSL, a widely used open-source cryptographic library, provides the foundational security protocols for a vast array of internet communications, including TLS and SSL. Its implementation is critical for securing web traffic (HTTPS), email, VPNs, and many other network services. The DTLS protocol, in particular, is essential for real-time applications like voice over IP (VoIP), online gaming, and streaming, where the reliability of TCP is less critical than the low latency offered by UDP. The potential for memory leakage in DTLS connections could therefore have significant implications for the security of these real-time communication channels.
The advisory from OpenSSL urges users to update to the patched versions of the library as soon as possible to mitigate the risk of exploitation. The specific versions addressed by the fix include OpenSSL 3.0.0 through 3.0.11, and 3.1.0 through 3.1.4. Users running older, unsupported versions of OpenSSL are also advised to upgrade to a supported release that includes the patch. The company has not disclosed details about whether this vulnerability has been actively exploited in the wild, but the high severity rating indicates a significant potential for harm if exploited. The fix involves adjustments to how handshake messages are handled during retransmissions to prevent the partial message from exposing memory contents.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.