Improper Validation of Specified Quantity in Input in OpenSSL - CVE-2026-75806

 

Improper Validation of Specified Quantity in Input in OpenSSL - CVE-2026-75806

Published: September 30, 2026


Vulnerability identifier: #VU152962
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-75806
CWE-ID: CWE-1284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper validation of specified quantity in input in DTLS 1.2 AEAD record processing when decrypting an unauthenticated record shorter than the explicit IV and authentication tag overhead. A remote attacker can send an undersized datagram to cause a denial of service.

The datagram must be routed to an existing DTLS 1.2 association using an AEAD cipher suite.


Affected software

OpenSSL
Debian Linux
openssl (Debian package)

How to mitigate CVE-2026-75806

Install security update from vendor's website.

OpenSSL - addressed in versions 1.0.2zs, 1.1.1zj, 3.0.23, 3.4.8, 3.5.9, 3.6.5, 4.0.3
openssl (Debian package) - update to 3.5.7-1~deb13u3

External References

Related Security Bulletins