CVE-2016-2179: OpenSSL
High severity, CVSS 7.5. EPSS: 26.6% chance of exploitation in the next 30 days.
The DTLS implementation in OpenSSL before 1.1.0 does not properly restrict the lifetime of queue entries associated with unused out-of-order messages, which allows remote attackers to cause a denial of service (memory consumption) by maintaining many crafted DTLS sessions simultaneously, related to d1_lib.c, statem_dtls.c, statem_lib.c, and statem_srvr.c.
Affected products
- OpenSSL OpenSSL: version 1.0.1 only; version 1.0.1a only; version 1.0.1b only; version 1.0.1c only; version 1.0.1d only; version 1.0.1e only; …
- Oracle Linux: version 6 only; version 7 only
Published 2016-09-16. Last modified 2026-06-17.