Memory Leak in OpenVPN Affects Key Extraction Process
CVE-2026-12932
7.1HIGH
What is CVE-2026-12932?
A vulnerability has been identified in the key extraction mechanism for the tls-crypt-v2 feature of OpenVPN, present in versions 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4. This flaw allows attackers to exploit a memory leak, enabling them to send a flood of specially crafted packets that can exhaust memory resources. Such an attack can lead to denial of service, disrupting the availability of vital network services. Users of affected versions are encouraged to review the security advisories and consider upgrading to mitigate this risk.
Affected Version(s)
OpenVPN 2.5.0 <= 2.6.20
OpenVPN 2.7_alpha1 <= 2.7.4