CVE-2016-2181: OpenSSL

High severity, CVSS 7.5. EPSS: 22.6% chance of exploitation in the next 30 days.

The Anti-Replay feature in the DTLS implementation in OpenSSL before 1.1.0 mishandles early use of a new epoch number in conjunction with a large sequence number, which allows remote attackers to cause a denial of service (false-positive packet drops) via spoofed DTLS records, related to rec_layer_d1.c and ssl3_record.c.

Affected products

  • OpenSSL OpenSSL: version 1.0.1 only; version 1.0.1a only; version 1.0.1b only; version 1.0.1c only; version 1.0.1d only; version 1.0.1e only; …
  • Oracle Linux: version 6 only; version 7 only

Published 2016-09-16. Last modified 2026-06-17.