Vulnerability record · CVE-2009-1386 · published 4 June 2009
CVE-2009-1386: OpenSSL DTLS NULL pointer dereference allows daemon crash
OOpenssl · Openssl
OpenSSL before 0.9.8i mishandles a DTLS ChangeCipherSpec packet received before ClientHello in ssl/s3_pkt.c, dereferencing a NULL pointer. A remote attacker can crash the DTLS daemon, causing a denial of service. The flaw is a straightforward availability issue with no confidentiality or integrity impact.
Description
ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a DTLS ChangeCipherSpec packet that occurs before ClientHello.
AV:N/AC:L/Au:N/C:N/I:N/A:P
Automated analysis
high priorityRemote, unauthenticated, low-complexity crash with public exploit code and very high EPSS, though impact is limited to denial of service.
What it is
OpenSSL before 0.9.8i mishandles a DTLS ChangeCipherSpec packet received before ClientHello in ssl/s3_pkt.c, dereferencing a NULL pointer. A remote attacker can crash the DTLS daemon, causing a denial of service. The flaw is a straightforward availability issue with no confidentiality or integrity impact.
Impact
An attacker gains only denial of service: the affected OpenSSL DTLS service crashes. There is no code execution, data disclosure, or data modification described.
Attack surface
Reachable over the network by sending a crafted DTLS ChangeCipherSpec packet before ClientHello; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.80, 99.6th percentile) and public exploit references exist (Exploit-DB 8873, SecurityFocus BID 35174), indicating mature public exploit code.
What to do
- Upgrade OpenSSL to 0.9.8i or later, or apply the vendor patch referenced in the OpenSSL change log (cn=17369).
- Apply distribution vendor updates for Red Hat, Ubuntu, and other affected packages (RHSA-2009-1335, USN-792-1).
- If DTLS is not required, disable DTLS listeners and restrict UDP exposure to trusted networks.
- Rate-limit or filter DTLS traffic at the network edge to reduce crash-triggering packet volume.
Detection
- Monitor DTLS daemon logs for crash or restart events correlated with inbound UDP traffic.
- Detect malformed DTLS handshakes where ChangeCipherSpec precedes ClientHello using IDS/IPS signatures.
- Track process uptime for OpenSSL-based DTLS services and alert on unexpected restarts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2009-1386 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2009-1386), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.