-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 ============================================================================= FreeBSD-SA-26:68.openssl Security Advisory The FreeBSD Project Topic: Out-of-bounds read in OpenSSL DTLS retransmission Category: contrib Module: openssl Announced: 2026-09-29 Credits: Laurent Gaffie (secorizon.com) Affects: All supported versions of FreeBSD. Corrected: 2026-09-29 15:56:25 UTC (stable/15, 15.1-STABLE) 2026-09-29 16:00:12 UTC (releng/15.1, 15.1-RELEASE-p4) 2026-09-29 15:59:21 UTC (releng/15.0, 15.0-RELEASE-p14) 2026-09-29 15:56:42 UTC (stable/14, 14.5-STABLE) 2026-09-29 16:09:12 UTC (releng/14.5, 14.5-RELEASE-p1) 2026-09-29 15:57:36 UTC (releng/14.4, 14.4-RELEASE-p10) CVE Name: CVE-2026-84782 For general information regarding FreeBSD Security Advisories, including descriptions of the fields above, security branches, and the following sections, please visit . Note: The upstream OpenSSL advisory also describes one Moderate and several Low severity issues. The Moderate issue, CVE-2026-84783, affects only OpenSSL 4.0 and does not affect FreeBSD. The Low severity issues are not addressed here: each was judged low risk, the fixes are extensive, and OpenSSL 3.0, used in FreeBSD 14.x, reached end of upstream support in September 2026. I. Background FreeBSD includes software from the OpenSSL Project. The OpenSSL Project is a collaborative effort to develop a robust, commercial-grade, full-featured Open Source toolkit for the Transport Layer Security (TLS) protocol. It is also a general-purpose cryptography library. Datagram Transport Layer Security (DTLS) is a variant of TLS for datagram transports such as UDP. Because datagrams may be lost, DTLS retransmits handshake messages when a timer expires without a response from the peer. II. Problem Description A DTLS handshake message write can be suspended part-way through when the underlying transport temporarily cannot accept more data. If the retransmission timer fired while such a write was suspended, the resent message reused the buffer and offset of the suspended write without resetting the offset. The resent message was read from that stale offset and could run past the end of the allocated buffer. The retransmission also overwrote state the suspended write needed in order to resume. III. Impact The retransmitted message may include heap memory contents, disclosing them to the DTLS peer as plaintext handshake data. If the read reaches unmapped memory, the application crashes, resulting in a Denial of Service (DoS). IV. Workaround No workaround is available, but applications that do not use DTLS are not affected. V. Solution Upgrade your vulnerable system to a supported FreeBSD stable or release / security branch (releng) dated after the correction date. Perform one of the following: 1) To update your vulnerable system installed from base system packages: Systems running a 15.0-RELEASE or later version of FreeBSD on the amd64 or arm64 platforms, which were installed using base system packages, can be updated via the pkg(8) utility: # pkg upgrade -r FreeBSD-base # shutdown -r +10min "Rebooting for a security update" 2) To update your vulnerable system installed from binary distribution sets: Systems running a RELEASE version of FreeBSD on the amd64 or arm64 platforms which were not installed using base system packages can be updated via the freebsd-update(8) utility: # freebsd-update fetch # freebsd-update install # shutdown -r +10min "Rebooting for a security update" 3) To update your vulnerable system via a source code patch: The following patches have been verified to apply to the applicable FreeBSD release branches. a) Download the relevant patch from the location below, and verify the detached PGP signature using your PGP utility. [FreeBSD 15.x] # fetch https://security.FreeBSD.org/patches/SA-26:68/openssl-15.patch # fetch https://security.FreeBSD.org/patches/SA-26:68/openssl-15.patch.asc # gpg --verify openssl-15.patch.asc [FreeBSD 14.x] # fetch https://security.FreeBSD.org/patches/SA-26:68/openssl-14.patch # fetch https://security.FreeBSD.org/patches/SA-26:68/openssl-14.patch.asc # gpg --verify openssl-14.patch.asc b) Apply the patch. Execute the following commands as root: # cd /usr/src # patch -E -p0 < /path/to/patch c) Recompile the operating system using buildworld and installworld as described in . Restart all daemons that use the library, or reboot the system. VI. Correction details This issue is corrected as of the corresponding Git commit hash in the following stable and release branches: Branch/path Hash Revision - ------------------------------------------------------------------------- stable/15/ ee87d97034b0 stable/15-n285683 releng/15.1/ f144a7164a1f releng/15.1-n283625 releng/15.0/ af45dd667d44 releng/15.0-n281124 stable/14/ 7b8e59ccbdfc stable/14-n275244 releng/14.5/ da952574154d releng/14.5-n274882 releng/14.4/ 49084ed8ecb5 releng/14.4-n273777 - ------------------------------------------------------------------------- Run the following command to see which files were modified by a particular commit: # git show --stat Or visit the following URL, replacing NNNNNN with the hash: To determine the commit count in a working tree (for comparison against nNNNNNN in the table above), run: # git rev-list --count --first-parent HEAD VII. References The latest revision of this advisory is available at -----BEGIN PGP SIGNATURE----- iQJPBAEBCgA5FiEEthUnfoEIffdcgYM7bljekB8AGu8FAmq8DL4bFIAAAAAABAAO bWFudTIsMi41KzEuMTIsMCwzAAoJEG5Y3pAfABrvbOIQAJ788IuUplEHQAyhJmZ9 k4Mfkh4FNe9G6E6cYGhcgNGYQ2rEFZ9uDIsElZJRHiG5JFs9jzKQl+l+jVabwj0r KW7h8nNkBVEvXzj3JBcrUNlaQADeuXAriHefKpg/8J9PXOY/Ae65E2OLzu4Daksq Kl0C9A61B7qOmtMU0Z2kbdSd2g0TdjN3MxvKvqXVdhV0npSd2vlf4N8/C6cOScrt OZ3nz/e3hjd/yi595Qn95KsoSGnUUv5Y7DFGSOoEub0iRyiTLLEaoFy5SnrNJSo1 LaPCF4KieRAywdHSTszDwwQz7cpHDONjyKyIXNF6ukH+Eq4upHCSwXgQRYhzMshK yUsRnzExXTjs7+v4t3XjgeY13TXtl6blEGpwShXVe2xyBNbb/co2tcr3LhLsRpDt W5DBZ733c5WXpojxh/uGVxfYHrstTnbAOnBhRSwfQ7P7RHdEUD3cgM/wVcPzI+Tc YDrb9v6Iqb/LA9NXgf90Y/FyxIdLcjvB8o0XRN7T0Zb2ZQYu3jbW2NPCg+Mi7WOU v3a0YgIBre6/pgnLvVI0Rh2Rq12R6gYUQOYEeqmxYqAvsPDDvxAKLkAvXbbZBq6/ 5v8PjeiBaW3a7dKJVahRfpAkRH9q4zItAMEPOKpObzD9S3Ve/k7SxFW/M8nYZ3lC N22KmBbuOi5xXmNVl/RJPqAK =qbjZ -----END PGP SIGNATURE-----