Impact
This vulnerability is a memory leak in the tls‑crypt‑v2 client key extraction routine in OpenVPN versions 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4. Remote attackers can send crafted packets that trigger the leak, causing memory exhaustion and a denial of service. The flaw does not provide any code execution, privilege escalation, or data disclosure; its impact is strictly on availability.
Affected Systems
OpenVPN software versions 2.5.0 to 2.6.20 and 2.7_alpha1 to 2.7.4 are impacted. The issue exists in builds that implement the tls‑crypt‑v2 authentication mechanism. Any deployment that uses these versions and the mentioned authentication method is susceptible.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity level. The EPSS score of less than 1% implies that, at present, the likelihood of exploitation is very low, and the vulnerability is not listed in CISA's KEV catalog, implying no known active exploitation. However, the description states that an attacker can trigger the flaw remotely by sending crafted packets; no explicit authentication requirement is mentioned. Successful exploitation results in memory exhaustion, causing the OpenVPN daemon to crash and denying VPN service until a restart or patch is applied.
OpenCVE Enrichment
Debian DLA
Debian DSA
Ubuntu USN