Impact
An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to trigger a use‑after‑free during TLS session promotion, potentially leading to a denial of service or memory leakage. The weakness corresponds to CWE-416.
Affected Systems
The vulnerability affects OpenVPN deployments running the affected versions: 2.6.0‑2.6.20 and 2.7_alpha1‑2.7.4. Any host or service using these OpenVPN builds is potentially exposed.
Risk and Exploitability
With a CVSS score of 6, the flaw presents a medium severity risk. The EPSS score is < 1% and the vulnerability is not listed in CISA’s KEV catalog. Attackers must first authenticate as a peer; however, once authenticated they can cause interruptive service failure or initiate memory disclosure in the OpenVPN process.
OpenCVE Enrichment
Debian DLA
Debian DSA
Ubuntu USN