{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-75806","assignerOrgId":"3a12439a-ef3a-4c79-92e6-6081a721f1e5","state":"PUBLISHED","assignerShortName":"openssl","dateReserved":"2026-08-18T09:34:32.659Z","datePublished":"2026-09-29T15:32:21.457Z","dateUpdated":"2026-09-29T16:53:23.785Z"},"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"OpenSSL","vendor":"OpenSSL","versions":[{"lessThan":"4.0.3","status":"affected","version":"4.0.0","versionType":"semver"},{"lessThan":"3.6.5","status":"affected","version":"3.6.0","versionType":"semver"},{"lessThan":"3.5.9","status":"affected","version":"3.5.0","versionType":"semver"},{"lessThan":"3.4.8","status":"affected","version":"3.4.0","versionType":"semver"},{"lessThan":"3.0.23","status":"affected","version":"3.0.0","versionType":"semver"},{"lessThan":"1.1.1zj","status":"affected","version":"1.1.1","versionType":"custom"}]}],"credits":[{"lang":"en","type":"reporter","value":"Mounir Idrassi"},{"lang":"en","type":"remediation developer","value":"Mounir Idrassi"}],"datePublic":"2026-09-29T14:21:57.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Issue summary: An established DTLS 1.2 association using an AEAD cipher suite<br>can be terminated by a single unauthenticated datagram whose encrypted<br>fragment is shorter than the mandatory explicit IV and authentication tag<br>overhead.<br><br>Impact summary: An attacker who can send a datagram that is routed to an<br>existing DTLS 1.2 association can tear that association down without knowing<br>any key material. This is a Denial of Service limited to the targeted<br>association. There is no memory safety or confidentiality impact.<br><br>CWE: CWE-1284: Improper Validation of Specified Quantity in Input<br><br>Description: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher<br>suite carries an explicit IV followed by the ciphertext and an authentication<br>tag. When decrypting such a record the record layer passed the record length to<br>the cipher implementation before checking that the record was long enough to<br>contain the explicit IV and the tag. For a record shorter than that overhead the<br>cipher implementation rejected the impossible length, and the record layer<br>treated this as an internal failure and raised a fatal internal_error alert<br>instead of treating the record as one that failed authentication.<br><br>In TLS 1.2 the same record causes a fatal internal_error alert instead of the<br>expected bad_record_mac alert. Since any undecryptable record already<br>terminates a TLS connection, this is a protocol conformance issue rather than<br>a security issue in TLS.<br><br>The fix validates the record length against the explicit IV and tag length<br>before any AEAD processing, so that TLS reports bad_record_mac and DTLS<br>silently discards the record.<br><br>FIPS impact: no<br>The affected code is outside the FIPS module boundary."}],"value":"Issue summary: An established DTLS 1.2 association using an AEAD cipher suite\ncan be terminated by a single unauthenticated datagram whose encrypted\nfragment is shorter than the mandatory explicit IV and authentication tag\noverhead.\n\nImpact summary: An attacker who can send a datagram that is routed to an\nexisting DTLS 1.2 association can tear that association down without knowing\nany key material. This is a Denial of Service limited to the targeted\nassociation. There is no memory safety or confidentiality impact.\n\nCWE: CWE-1284: Improper Validation of Specified Quantity in Input\n\nDescription: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher\nsuite carries an explicit IV followed by the ciphertext and an authentication\ntag. When decrypting such a record the record layer passed the record length to\nthe cipher implementation before checking that the record was long enough to\ncontain the explicit IV and the tag. For a record shorter than that overhead the\ncipher implementation rejected the impossible length, and the record layer\ntreated this as an internal failure and raised a fatal internal_error alert\ninstead of treating the record as one that failed authentication.\n\nIn TLS 1.2 the same record causes a fatal internal_error alert instead of the\nexpected bad_record_mac alert. Since any undecryptable record already\nterminates a TLS connection, this is a protocol conformance issue rather than\na security issue in TLS.\n\nThe fix validates the record length against the explicit IV and tag length\nbefore any AEAD processing, so that TLS reports bad_record_mac and DTLS\nsilently discards the record.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary."}],"metrics":[{"format":"other","other":{"content":{"text":"Low"},"type":"https://openssl-library.org/policies/general/security-policy/"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-1284","description":"CWE-1284 Improper Validation of Specified Quantity in Input","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"3a12439a-ef3a-4c79-92e6-6081a721f1e5","shortName":"openssl","dateUpdated":"2026-09-29T15:32:21.457Z"},"references":[{"name":"OpenSSL Advisory","tags":["vendor-advisory"],"url":"https://openssl-library.org/news/secadv/20260929.txt"},{"name":"4.0.3 git commit","tags":["patch"],"url":"https://github.com/openssl/openssl/commit/04728a289a823e68137f88da016cb9ede307217d"},{"name":"3.6.5 git commit","tags":["patch"],"url":"https://github.com/openssl/openssl/commit/050b275cd671a6eed1d6457642d41a5a77aab972"},{"name":"3.5.9 git commit","tags":["patch"],"url":"https://github.com/openssl/openssl/commit/3a4589d015a9049d47b66f186cf50a8711343a1d"},{"name":"3.4.8 git commit","tags":["patch"],"url":"https://github.com/openssl/openssl/commit/5af82fefbaf2b5fec2fc0e1d87f112844902f01d"}],"source":{"discovery":"UNKNOWN"},"title":"Unauthenticated and Undersized DTLS 1.2 AEAD Record Causes DoS","x_generator":{"engine":"Vulnogram 0.2.0"}},"adp":[{"metrics":[{"cvssV3_1":{"scope":"UNCHANGED","version":"3.1","baseScore":5.3,"attackVector":"NETWORK","baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","integrityImpact":"NONE","userInteraction":"NONE","attackComplexity":"LOW","availabilityImpact":"LOW","privilegesRequired":"NONE","confidentialityImpact":"NONE"}},{"other":{"type":"ssvc","content":{"timestamp":"2026-09-29T16:52:47.298458Z","id":"CVE-2026-75806","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-29T16:53:23.785Z"}}]}}