Bug 2543260 (CVE-2026-75806)
| Summary: | CVE-2026-75806 openssl: OpenSSL: Denial of Service via undersized DTLS record | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | abarbaro, akhatavk, alizardo, anthomas, aos-team-art-private, asdas, csutherl, dpaolell, ehelms, ggainey, jchui, jclere, jdelft, jhe, jpasqual, jupierce, juwatts, ktsao, lgarciaa, mbiarnes, mdellweg, mhulan, nboldt, nmoumoul, oaljalju, osousa, pcreech, pjindal, plodge, ppalepu, ppostler, prdhamdh, psrna, rchan, rhel-process-autobot, sghai, sidsharm, smallamp, suppawar, szappis, tmalecek, vchlup, vlaad, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in OpenSSL. A remote, unauthenticated attacker can cause a Denial of Service (DoS) by terminating an active Datagram Transport Layer Security (DTLS) session. By sending an undersized network packet that is shorter than the expected cryptographic overhead, the record processing layer fails to validate the packet length and misinterprets the packet as an internal error rather than an authentication failure. This improper handling triggers a fatal alert that unexpectedly closes the targeted connection without requiring valid encryption keys.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-09-29 15:54:59 UTC
|