Improper Validation of Specified Quantity in Input in OpenSSL - CVE-2026-75806
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper validation of specified quantity in input in DTLS 1.2 AEAD record processing when decrypting an unauthenticated record shorter than the explicit IV and authentication tag overhead. A remote attacker can send an undersized datagram to cause a denial of service.
The datagram must be routed to an existing DTLS 1.2 association using an AEAD cipher suite.
Affected software
Debian Linux
openssl (Debian package)
How to mitigate CVE-2026-75806
openssl (Debian package) - update to 3.5.7-1~deb13u3