Description
A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to potentially cause a denial of service or leak memory via crafted packets during TLS session promotion or expiry
Published: 2026-07-30
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free flaw exists in OpenVPN versions 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4. An authenticated peer can send specially crafted packets during TLS session promotion or expiry to potentially trigger a crash, resulting in denial of service, or cause memory leakage. The weakness is a use‑after‑free (CWE‑416) combined with a memory‑access violation (CWE‑125).

Affected Systems

The vulnerability affects the OpenVPN software produced by OpenVPN Systems. It is present in all releases from 2.6.0 to 2.6.20 and from 2.7_alpha1 to 2.7.4, regardless of platform, as long as TLS session promotion or expiry is enabled.

Risk and Exploitability

The CVSS score of 6 indicates a moderate severity. The EPSS score is < 1%, indicating a very low probability of exploitation. The vulnerability is not listed in CISA's KEV catalog, suggesting no publicly known exploits. The attack vector requires an attacker to be an authenticated peer, possessing valid client credentials, and to transmit crafted packets during TLS session promotion or expiry to trigger the flaw.

Generated by OpenCVE AI on August 2, 2026 at 05:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade OpenVPN to the latest patched release (2.6.21 or newer, or 2.7.5 or newer) and deploy the updated binaries across all servers.
  • Configure the server to accept authentication only from trusted users and enforce stringent client‑certificate checks to shrink the potential attacker set.
  • Enable detailed logging of TLS session promotion and expiry events, and implement anomaly detection or alerting for unusual packet patterns that could indicate an attempted exploitation.

Generated by OpenCVE AI on August 2, 2026 at 05:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4666-1 openvpn security update
Debian DLA Debian DLA DLA-4653-2 openvpn regression update
Debian DSA Debian DSA DSA-6376-1 openvpn security update
Ubuntu USN Ubuntu USN USN-8540-1 OpenVPN vulnerabilities
History

Sat, 01 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title OpenVPN: OpenVPN: Denial of Service or memory leak via crafted packets
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H'}

threat_severity

Moderate


Fri, 31 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Openvpn
Openvpn openvpn
Vendors & Products Openvpn
Openvpn openvpn

Thu, 30 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Description A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to potentially cause a denial of service or leak memory via crafted packets during TLS session promotion or expiry
Weaknesses CWE-125
CWE-416
References
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Debian Debian Linux
Openvpn Openvpn
cve-icon MITRE

Status: PUBLISHED

Assigner: OpenVPN

Published:

Updated: 2026-07-30T18:07:17.597Z

Reserved: 2026-06-23T13:16:10.234Z

Link: CVE-2026-12996

cve-icon Vulnrichment

Updated: 2026-07-30T17:33:47.338Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T17:16:28.450

Modified: 2026-08-05T19:38:07.560

Link: CVE-2026-12996

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-30T16:38:58Z

Links: CVE-2026-12996 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T05:15:15Z

Weaknesses