CyberSecurity News
OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted
AI summary
OpenSSL has fixed a high-severity flaw in its DTLS implementation that can cause heap memory to be leaked unencrypted to the other side of a connection or result in a program crash. The vulnerability is related to the resend mechanism used in DTLS when no reply is received before a timer expires. Specifically, the issue occurs when a resend is initiated while a larger handshake message is partially sent. This can lead to either a memory leak or a crash. The fix was released by OpenSSL, addressing the potential security issue in its DTLS protocol.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

