Impact
The flaw is a memory leak triggered when OpenVPN processes TLS‑Crypt‑V2 client keys. The leak causes the server to gradually exhaust heap memory, eventually making the VPN service unresponsive or terminating it. This manifests as a denial of service for all VPN users, and the weakness is recognized as a classic heap usage error (CWE‑401) combined with a lack of resource limits (CWE‑770).
Affected Systems
OpenVPN releases 2.5.0 through 2.5.11, 2.6.0 through 2.6.20, and 2.7_alpha1 through 2.7.4 that enable TLS‑Crypt‑V2 client authentication are affected. Deployments using these versions with TLS‑Crypt‑V2 are at risk, while other OpenVPN products or older releases are not listed.
Risk and Exploitability
The CVSS score of 6.0 indicates medium severity, and the EPSS of < 1% reflects a low exploitation probability. Exploitation requires possession of a valid TLS‑Crypt‑V2 client key, meaning the attacker must first authenticate or compromise a client key. Once authenticated, repeated connection attempts can trigger the leak, leading to a gradual denial of service over time.
OpenCVE Enrichment
Debian DLA
Debian DSA
Ubuntu USN