← Vulnerability feed

Vulnerability record · CVE-2016-6309 · published 26 September 2016

CVE-2016-6309: OpenSSL 1.1.0a statem use-after-free on realloc in TLS session handling

OOpenssl · Openssl

OpenSSL 1.1.0a's statem/statem.c fails to account for memory-block movement after a realloc call, leaving a dangling pointer that can be used after free. A remote attacker can trigger this through a crafted TLS session, causing a denial of service or potentially arbitrary code execution. The flaw is rated critical (CVSS 3.0 9.8) and affects only the stated 1.1.0a version per the description.

9.8 CVSS 3.0 Critical EPSS 70% · top 0.6% CWE-416 · Use after free
9.8CVSS 3.0 base score, v2 10.0
70%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
28References
17 Jun 2026Last modified by NVD

Description

statem/statem.c in OpenSSL 1.1.0a does not consider memory-block movement after a realloc call, which allows remote attackers to cause a denial of service (use-after-free) or possibly execute arbitrary code via a crafted TLS session.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityCVSS 3.0 score is 9.8 with network reachability, no privileges or interaction, and high confidentiality, integrity and availability impact, plus a very high EPSS percentile.

What it is

OpenSSL 1.1.0a's statem/statem.c fails to account for memory-block movement after a realloc call, leaving a dangling pointer that can be used after free. A remote attacker can trigger this through a crafted TLS session, causing a denial of service or potentially arbitrary code execution. The flaw is rated critical (CVSS 3.0 9.8) and affects only the stated 1.1.0a version per the description.

Impact

An unauthenticated remote attacker can crash the TLS service (denial of service) or, in the worst case, execute arbitrary code in the context of the affected process.

Attack surface

Reached over the network via a crafted TLS session; the CVSS vector shows no privileges or user interaction required. No authentication is needed to send the triggering TLS traffic.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.70223, 99.3rd percentile), indicating elevated likelihood of exploitation activity. No reference is tagged as exploit code, so public exploit availability is not confirmed by this record.

What to do

  • Upgrade OpenSSL to a version later than 1.1.0a that includes the fix (see the OpenSSL security advisory 20160926 and commit acacbfa7565c78d2273c0b2a2e5e803f44afefeb).
  • Inventory and update downstream products that bundle OpenSSL 1.1.0a, including Oracle, Juniper, IBM, HPE and Blue Coat/Symantec offerings referenced in the advisories.
  • If immediate upgrade is not possible, restrict or monitor TLS exposure on affected services and apply vendor-supplied patches as they become available.
  • Verify the OpenSSL version in use across servers, appliances and embedded devices, since the affected version is narrow and easy to miss.

Detection

  • Monitor for crashes or abnormal process termination in services linked against OpenSSL 1.1.0a, especially during TLS handshakes.
  • Watch for repeated malformed or unusual TLS session traffic targeting affected endpoints that precedes service instability.
  • Use memory-safety tooling (ASan, valgrind) in test environments to confirm use-after-free behavior when reproducing the crafted TLS session.
  • Track vendor advisories and asset inventories for OpenSSL 1.1.0a to identify unpatched instances.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759
http://www-01.ibm.com/support/docview.wss?uid=swg21995039
http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html
http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html
http://www.securityfocus.com/bid/93177
http://www.securitytracker.com/id/1036885
https://bto.bluecoat.com/security-advisory/sa132
https://git.openssl.org/?p=openssl.git%3Ba=commit%3Bh=acacbfa7565c78d2273c0b2a2e5e803f44afefeb
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03856en_us
https://www.openssl.org/news/secadv/20160926.txt Vendor Advisory
https://www.tenable.com/security/tns-2016-16
https://www.tenable.com/security/tns-2016-20
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759
http://www-01.ibm.com/support/docview.wss?uid=swg21995039
http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html
http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html
http://www.securityfocus.com/bid/93177
http://www.securitytracker.com/id/1036885
https://bto.bluecoat.com/security-advisory/sa132
https://git.openssl.org/?p=openssl.git%3Ba=commit%3Bh=acacbfa7565c78d2273c0b2a2e5e803f44afefeb
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03856en_us
https://www.openssl.org/news/secadv/20160926.txt Vendor Advisory
https://www.tenable.com/security/tns-2016-16
https://www.tenable.com/security/tns-2016-20

Track CVE-2016-6309 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2014-0160OpenSSL TLS/DTLS Heartbeat Extension Out-of-Bounds Read (Heartbleed)OpenSSL 1.0.1 before 1.0.1g mishandles Heartbeat Extension packets in its TLS and DTLS implementations, causing an out-of-bounds read of process memo…KEVEPSS 100%analysed10.0CVE-2009-3245Openssl improper input validation vulnerabilityOpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand function calls in (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3) c…EPSS 6.5%10.0CVE-2006-3738OpenSSL SSL_get_shared_ciphers buffer overflow via long cipher listOpenSSL versions before 0.9.7l and 0.9.8d contain a buffer overflow in the SSL_get_shared_ciphers function, triggered by a long list of ciphers. The …EPSS 49%analysed9.8CVE-2026-63073Openssl vulnerabilityIssue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the format string to `ERR_raise_da…EPSS 1.2%9.8CVE-2026-31789Openssl out-of-bounds write vulnerabilityIssue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms. Impact…EPSS 0.33%9.8CVE-2022-2274OpenSSL 3.0.4 RSA AVX512IFMA memory corruptionOpenSSL 3.0.4 introduced a bug in the RSA implementation for X86_64 CPUs supporting AVX512IFMA instructions, causing 2048-bit private key operations …EPSS 46%analysed9.8CVE-2021-3711OpenSSL SM2 decryption buffer overflowOpenSSL's SM2 decryption code miscalculates the output buffer size needed by EVP_PKEY_decrypt(), so the first sizing call can return a value smaller …EPSS 88%analysed9.8CVE-2016-6303Nodejs node.js out-of-bounds write vulnerabilityInteger overflow in the MDC2_Update function in crypto/mdc2/mdc2dgst.c in OpenSSL before 1.1.0 allows remote attackers to cause a denial of service (…EPSS 32%

Source: NIST National Vulnerability Database (record CVE-2016-6309), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.