CVE-2026-54874: Excessive Memory Use Buffering DTLS Records for a Future Epoch
Published Aug 25, 2026
·Updated
Issue summary: Receiving a DTLS record for a future epoch while a handshake is in progress causes OpenSSL to buffer far more memory than the record itself requires.
Affected Software
8 affected components
OpenSSL OpenSSL<=4.0.1
OpenSSL OpenSSL<=3.6.3
OpenSSL OpenSSL<=3.5.7
OpenSSL OpenSSL<=3.4.6
OpenSSL OpenSSL<=3.0.21
OpenSSL OpenSSL<=1.1.1y
OpenSSL OpenSSL<=1.0.2q
debian/openssl<=1.1.1w-0+deb11u1, <=1.1.1w-0+deb11u8, <=3.0.20-1~deb12u2, <=3.5.6-1~deb13u2, <=3.6.3-1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenSSL 1.0.2to a version that resolves this vulnerability.Fixed in 1.0.2zr - Upgrade
Upgrade
OpenSSL 1.1.1to a version that resolves this vulnerability.Fixed in 1.1.1zi - Upgrade
Upgrade
OpenSSL 3.0to a version that resolves this vulnerability.Fixed in 3.0.22 - Upgrade
Upgrade
OpenSSL 3.4to a version that resolves this vulnerability.Fixed in 3.4.7 - Upgrade
Upgrade
OpenSSL 3.5to a version that resolves this vulnerability.Fixed in 3.5.8 - Upgrade
Upgrade
OpenSSL 3.6to a version that resolves this vulnerability.Fixed in 3.6.4 - Upgrade
Upgrade
OpenSSL 4.0to a version that resolves this vulnerability.Fixed in 4.0.2
Event History
Aug 25, 2026
CVE Published
via MITRE·12:59 PM
Data Sourced
via MITRE·12:59 PM
DescriptionWeakness
Data Sourced
via NVD·01:19 PM
DescriptionSeverityWeakness
Data Sourced
via Ubuntu·07:09 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·07:11 PM
DescriptionAffected Software
Data Sourced
via Launchpad·07:11 PM
Description