Executive brief
OpenSSL's DTLS (Datagram TLS) implementation buffers incoming records that arrive early from the peer before the handshake is complete. An attacker can send a stream of forged small records claiming to belong to a future epoch, causing the server to retain disproportionately large amounts of memory (around 1.7 MB per connection) despite sending only a small amount of network data. This creates a remote denial-of-service risk by exhausting server memory, particularly when an attacker opens many concurrent connections.
Technical details
The vulnerability is an asymmetric resource consumption issue (CWE-405) in OpenSSL's DTLS record handling. When a handshake is in progress, the implementation buffers records destined for future epochs to handle legitimate reordering on unreliable UDP transports. However, each buffered record retains the entire read buffer (~16 KB) rather than just the record bytes, allowing up to 100 records per connection. An unauthenticated network attacker can send forged small records claiming to belong to the next epoch, achieving a memory amplification factor of approximately 1200:1. No authentication is required; the attack exploits the early buffering mechanism before epoch transitions are verified. The fix is available in OpenSSL 4.0.2, 3.6.4, 3.5.8, 3.4.7, and 3.0.22 (or 1.1.1zi and 1.0.2zr for premium support customers).
Affected products
- OpenSSL OpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1, 1.0.2
Timeline
- 2026-05-18: disclosed: Reported by Amazon Web Services
- 2026-08-25: patched: Fixed in OpenSSL 4.0.2, 3.6.4, 3.5.8, 3.4.7, 3.0.22, and 1.1.1zi/1.0.2zr (premium support)
- 2026-08-25: advisory: CVE-2026-54874 published