Impact
A memory leak is triggered in OpenVPN when it processes TLS‑Crypt‑V2 client keys, allowing remote attackers who hold a valid client key to exhaust the server’s memory resources. The exhaustion can cause the VPN service to become unresponsive or terminate, effectively denying legitimate users access. This flaw is a classic heap usage error identified by CWE‑401 and a lack of proper resource limits indicated by CWE‑770.
Affected Systems
OpenVPN versions 2.5.0 through 2.5.11, 2.6.0 through 2.6.20, and 2.7_alpha1 through 2.7.4 are affected. Any deployment of these releases that enables TLS‑Crypt‑V2 client authentication is vulnerable, while other products or older releases are not listed.
Risk and Exploitability
The CVSS score of 6.0 reflects medium severity, and the EPSS score of < 1% shows a low likelihood of exploitation. Because the flaw requires an attacker to possess a valid TLS‑Crypt‑V2 client key, prior authentication or a compromised key is necessary. Once authenticated, an attacker can repeatedly initiate connections to trigger the leak, leading over time to a denial of service.
OpenCVE Enrichment
Debian DLA
Debian DSA
Ubuntu USN