CVE-2016-2179: OpenSSL

High severity, CVSS 7.5. EPSS: 26.6% chance of exploitation in the next 30 days.

The DTLS implementation in OpenSSL before 1.1.0 does not properly restrict the lifetime of queue entries associated with unused out-of-order messages, which allows remote attackers to cause a denial of service (memory consumption) by maintaining many crafted DTLS sessions simultaneously, related to d1_lib.c, statem_dtls.c, statem_lib.c, and statem_srvr.c.

Affected products

  • OpenSSL OpenSSL: version 1.0.1 only; version 1.0.1a only; version 1.0.1b only; version 1.0.1c only; version 1.0.1d only; version 1.0.1e only; …
  • Oracle Linux: version 6 only; version 7 only

Published 2016-09-16. Last modified 2026-06-17.