Vulnerability record · CVE-2016-6309 · published 26 September 2016
CVE-2016-6309: OpenSSL 1.1.0a statem use-after-free on realloc in TLS session handling
OOpenssl · Openssl
OpenSSL 1.1.0a's statem/statem.c fails to account for memory-block movement after a realloc call, leaving a dangling pointer that can be used after free. A remote attacker can trigger this through a crafted TLS session, causing a denial of service or potentially arbitrary code execution. The flaw is rated critical (CVSS 3.0 9.8) and affects only the stated 1.1.0a version per the description.
Description
statem/statem.c in OpenSSL 1.1.0a does not consider memory-block movement after a realloc call, which allows remote attackers to cause a denial of service (use-after-free) or possibly execute arbitrary code via a crafted TLS session.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 3.0 score is 9.8 with network reachability, no privileges or interaction, and high confidentiality, integrity and availability impact, plus a very high EPSS percentile.
What it is
OpenSSL 1.1.0a's statem/statem.c fails to account for memory-block movement after a realloc call, leaving a dangling pointer that can be used after free. A remote attacker can trigger this through a crafted TLS session, causing a denial of service or potentially arbitrary code execution. The flaw is rated critical (CVSS 3.0 9.8) and affects only the stated 1.1.0a version per the description.
Impact
An unauthenticated remote attacker can crash the TLS service (denial of service) or, in the worst case, execute arbitrary code in the context of the affected process.
Attack surface
Reached over the network via a crafted TLS session; the CVSS vector shows no privileges or user interaction required. No authentication is needed to send the triggering TLS traffic.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.70223, 99.3rd percentile), indicating elevated likelihood of exploitation activity. No reference is tagged as exploit code, so public exploit availability is not confirmed by this record.
What to do
- Upgrade OpenSSL to a version later than 1.1.0a that includes the fix (see the OpenSSL security advisory 20160926 and commit acacbfa7565c78d2273c0b2a2e5e803f44afefeb).
- Inventory and update downstream products that bundle OpenSSL 1.1.0a, including Oracle, Juniper, IBM, HPE and Blue Coat/Symantec offerings referenced in the advisories.
- If immediate upgrade is not possible, restrict or monitor TLS exposure on affected services and apply vendor-supplied patches as they become available.
- Verify the OpenSSL version in use across servers, appliances and embedded devices, since the affected version is narrow and easy to miss.
Detection
- Monitor for crashes or abnormal process termination in services linked against OpenSSL 1.1.0a, especially during TLS handshakes.
- Watch for repeated malformed or unusual TLS session traffic targeting affected endpoints that precedes service instability.
- Use memory-safety tooling (ASan, valgrind) in test environments to confirm use-after-free behavior when reproducing the crafted TLS session.
- Track vendor advisories and asset inventories for OpenSSL 1.1.0a to identify unpatched instances.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-6309 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-6309), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.