{"id":"CVE-2026-75806","summary":"Unauthenticated and Undersized DTLS 1.2 AEAD Record Causes DoS","details":"Issue summary: An established DTLS 1.2 association using an AEAD cipher suite\ncan be terminated by a single unauthenticated datagram whose encrypted\nfragment is shorter than the mandatory explicit IV and authentication tag\noverhead.\n\nImpact summary: An attacker who can send a datagram that is routed to an\nexisting DTLS 1.2 association can tear that association down without knowing\nany key material. This is a Denial of Service limited to the targeted\nassociation. There is no memory safety or confidentiality impact.\n\nCWE: CWE-1284: Improper Validation of Specified Quantity in Input\n\nDescription: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher\nsuite carries an explicit IV followed by the ciphertext and an authentication\ntag. When decrypting such a record the record layer passed the record length to\nthe cipher implementation before checking that the record was long enough to\ncontain the explicit IV and the tag. For a record shorter than that overhead the\ncipher implementation rejected the impossible length, and the record layer\ntreated this as an internal failure and raised a fatal internal_error alert\ninstead of treating the record as one that failed authentication.\n\nIn TLS 1.2 the same record causes a fatal internal_error alert instead of the\nexpected bad_record_mac alert. Since any undecryptable record already\nterminates a TLS connection, this is a protocol conformance issue rather than\na security issue in TLS.\n\nThe fix validates the record length against the explicit IV and tag length\nbefore any AEAD processing, so that TLS reports bad_record_mac and DTLS\nsilently discards the record.\n\nFIPS impact: no\nThe affected code is outside the FIPS module boundary.","modified":"2026-09-30T08:16:01.687664019Z","published":"2026-09-29T15:32:21.457Z","database_specific":{"cna_assigner":"openssl","cwe_ids":["CWE-1284"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/75xxx/CVE-2026-75806.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"3.0.0"},{"fixed":"3.0.23"}]}]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/75xxx/CVE-2026-75806.json"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/04728a289a823e68137f88da016cb9ede307217d"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/050b275cd671a6eed1d6457642d41a5a77aab972"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/3a4589d015a9049d47b66f186cf50a8711343a1d"},{"type":"FIX","url":"https://github.com/openssl/openssl/commit/5af82fefbaf2b5fec2fc0e1d87f112844902f01d"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-75806"},{"type":"ADVISORY","url":"https://openssl-library.org/news/secadv/20260929.txt"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/openssl/openssl","events":[{"introduced":"11b7b6ea3b65a584e1d31408ed1bdb139465cffd"},{"fixed":"af1775b60dfa141a4ad762585052cabeb9f37e9e"},{"introduced":"7b371d80d959ec9ab4139d09d78e83c090de9779"},{"fixed":"c8bd5a57108599ac650bbae77fcabe3109dab2e8"},{"introduced":"636dfadc70ce26f2473870570bfd9ec352806b1d"},{"fixed":"45e844fa2a14ec92d146bd8f5778ac130b6625fb"},{"introduced":"98acb6b02839c609ef5b837794e08d906d965335"},{"fixed":"e72c946f6f6d94c8ba5119acb25340b7b6b2073f"},{"introduced":"e04bd3433fd84e1861bf258ea37928d9845e6a86"},{"fixed":"e04bd3433fd84e1861bf258ea37928d9845e6a86"}],"database_specific":{"extracted_events":[{"introduced":"4.0.0"},{"fixed":"4.0.3"},{"introduced":"3.6.0"},{"fixed":"3.6.5"},{"introduced":"3.5.0"},{"fixed":"3.5.9"},{"introduced":"3.4.0"},{"fixed":"3.4.8"},{"introduced":"1.1.1"},{"fixed":"1.1.1zj"}],"source":"AFFECTED_FIELD"}}],"versions":["openssl-3.4.7","openssl-3.5.8","openssl-3.6.4","openssl-4.0.2","openssl-3.4.6","openssl-3.5.7","openssl-3.6.3","openssl-4.0.1","openssl-4.0.0","openssl-3.4.5","openssl-3.5.6","openssl-3.6.2","openssl-3.4.4","openssl-3.5.5","openssl-3.6.1","3.4-POST-CLANG-FORMAT-WEBKIT","3.4-PRE-CLANG-FORMAT-WEBKIT","3.5-POST-CLANG-FORMAT-WEBKIT","3.5-PRE-CLANG-FORMAT-WEBKIT","3.6-POST-CLANG-FORMAT-WEBKIT","3.6-PRE-CLANG-FORMAT-WEBKIT","openssl-3.6.0","openssl-3.4.3","openssl-3.5.4","openssl-3.5.3","openssl-3.5.2","openssl-3.4.2","openssl-3.5.1","openssl-3.5.0","openssl-3.4.1","openssl-3.4.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-75806.json","vanir_signatures":[{"digest":{"line_hashes":["28170854778703993674264004058177114599","73132526844288570625317440636111911761","177405411499435185068645597737938634778","224809958623850711330610094965797758930","295554444428855106393106961197201359586"],"threshold":0.9},"id":"CVE-2026-75806-c377fa22","signature_type":"Line","signature_version":"v1","source":"https://github.com/openssl/openssl/commit/e04bd3433fd84e1861bf258ea37928d9845e6a86","target":{"file":"include/openssl/opensslv.h"},"deprecated":false}],"vanir_signatures_modified":"2026-09-30T08:16:01Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}]}