CVE-2026-84782: DTLS Retransmits Handshake Messages From a Stale Buffer Offset
DTLS Retransmits Handshake Messages From a Stale Buffer Offset
Other sources
Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read past the message buffer and the retransmission overwrites the internal state the suspended write needs to resume correctly.
— Launchpad
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Deployments using DTLS are exposed when a handshake message is written in fragments and the write suspends with WANT_WRITE because the transport temporarily cannot accept more data. The retransmission timer must then fire while that write remains suspended.
What could an affected peer observe or cause?
The peer can receive heap memory disclosed as plaintext handshake data if retransmission reads past the intended message buffer. The condition can also cause a crash and denial of service when the read reaches an unmapped memory region.