Back

HIGH

openssl: DTLS replay protection bypass allows DoS against DTLS connection

Published Sep 16, 2016

Description

The Anti-Replay feature in the DTLS implementation in OpenSSL before 1.1.0 mishandles early use of a new epoch number in conjunction with a large sequence number, which allows remote attackers to cause a denial of service (false-positive packet drops) via spoofed DTLS records, related to rec_layer_d1.c and ssl3_record.c.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (46)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Sep 16, 2016
Updated Aug 5, 2024
Reserved Jan 29, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jul 5, 2016