Use-After-Free Vulnerability in OpenVPN by OpenVPN Technologies
CVE-2026-12996
6MEDIUM
What is CVE-2026-12996?
A use-after-free vulnerability exists in versions 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 of OpenVPN. This flaw could allow remote authenticated peers to exploit crafted packets during the promotion or expiry of TLS sessions, potentially leading to a denial-of-service condition or memory leakage. It is essential for users of affected versions to apply the necessary patches to safeguard against this vulnerability.
Affected Version(s)
OpenVPN 2.6.0 <= 2.6.20
OpenVPN 2.7_alpha1 <= 2.7.4