Sceawere
Vulnerability Detail
CVE-2026-75806UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
DTLS 1.2 AEAD Record Termination
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 9h ago
- Vendor
- OpenSSL
- Product
- OpenSSL
- Attack Type
- CWE-1284 Improper Validation of Specified Quantity in Input
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Issue summary: An established DTLS 1.2 association using an AEAD cipher suite can be terminated by a single unauthenticated datagram whose encrypted fragment is shorter than the mandatory explicit IV and authentication tag overhead. Impact summary: An attacker who can send a datagram that is routed to an existing DTLS 1.2 association can tear that association down without knowing any key material. This is a Denial of Service limited to the targeted association. There is no memory safety or confidentiality impact. CWE: CWE-1284: Improper Validation of Specified Quantity in Input Description: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher suite carries an explicit IV followed by the ciphertext and an authentication tag. When decrypting such a record the record layer passed the record length to the cipher implementation before checking that the record was long enough to contain the explicit IV and the tag. For a record shorter than that overhead the cipher implementation rejected the impossible length, and the record layer treated this as an internal failure and raised a fatal internal_error alert instead of treating the record as one that failed authentication. In TLS 1.2 the same record causes a fatal internal_error alert instead of the expected bad_record_mac alert. Since any undecryptable record already terminates a TLS connection, this is a protocol conformance issue rather than a security issue in TLS. The fix validates the record length against the explicit IV and tag length before any AEAD processing, so that TLS reports bad_record_mac and DTLS silently discards the record. FIPS impact: no The affected code is outside the FIPS module boundary.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-09-29T16:17:11.217Z",
"pubdate": "2026-09-29T16:17:11.217Z",
"executiveSummary": "This vulnerability involves an improper validation of record length in DTLS 1.2 and TLS 1.2 implementations using AEAD (Authenticated Encryption with Associated Data) cipher suites, classified under CWE-1284.\nThe vulnerability allows an unauthenticated, remote attacker to trigger a Denial of Service (DoS) by sending a specially crafted, malformed datagram to an active association.\nIn the context of DTLS 1.2, this results in the immediate teardown of a targeted session, as the implementation prematurely treats a malformed length input as a fatal internal error rather than a authentication failure.\nWhile TLS 1.2 is also affected, the impact is primarily a protocol conformance issue, as existing TLS error handling already mandates connection termination for undecryptable records.\nThe vulnerability requires no authentication and no prior knowledge of session keys, making it a viable DoS vector for any attacker capable of injecting packets into an existing association's path.\nThere are no impacts regarding memory safety, confidentiality, or data exfiltration. The issue is localized to the record layer processing logic.",
"technicalDetails": "The root cause of this vulnerability lies in the record layer's failure to validate the total length of an incoming AEAD-protected record before passing that length parameter to the underlying cipher implementation.\nIn both TLS 1.2 and DTLS 1.2, AEAD cipher suites dictate a specific structure for protected records: an explicit Initialization Vector (IV), followed by the ciphertext, and finally the authentication tag (MAC).\nWhen a datagram is received that is shorter than the combined length of the explicit IV and the authentication tag, the cipher implementation correctly identifies the length as physically impossible for processing. However, the record layer does not account for this state.\nBecause the record layer invokes the cipher implementation without prior bounds checking, the implementation returns an error due to the undersized input. The record layer interprets this error as an 'internal_error' alert, which forces the state machine into a fatal error state.\nIn a DTLS 1.2 association, this causes the protocol to tear down the entire session. This is distinct from standard protocol behavior, which would expect a silent discard or a 'bad_record_mac' alert for records that fail cryptographic verification, rather than a catastrophic internal failure.\nThe attack flow is straightforward: an attacker identifies an active DTLS 1.2 association and injects a single, malformed datagram containing a record length field that is smaller than the mandated overhead for the AEAD cipher in use. Upon receipt, the target system's record layer attempts to process the payload, hits the validation failure in the cipher module, generates the fatal internal_error alert, and terminates the association.\nThis vulnerability is strictly a protocol-level implementation flaw. It does not allow for unauthorized access to data, nor does it provide a vector for arbitrary code execution. The security risk is limited to the ability of a remote, unauthenticated party to force the termination of existing encrypted channels. In environments where DTLS is used for high-availability signaling or stream management, this can effectively interrupt service for specific clients."
}