<Vulnerability name="CVE-2026-78221">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Important</ThreatSeverity>
    <PublicDate>2026-09-07T07:28:14</PublicDate>
    <Bugzilla id="2529297" url="https://bugzilla.redhat.com/show_bug.cgi?id=2529297" xml:lang="en:us">
OpenVPN: OpenVPN: Memory corruption and information disclosure vulnerability
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>7.5</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-120</CWE>
    <Details xml:lang="en:us" source="Mitre">
An incorrect buffer size calculation in the Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to cause memory corruption or disclose sensitive information via crafted NRPT inputs.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in OpenVPN. An incorrect buffer size calculation within the Windows Interactive Service allows local authenticated users to trigger memory corruption or disclose sensitive information. This vulnerability can be exploited by providing specially crafted inputs.
    </Details>
    <Statement xml:lang="en:us">
Important: This vulnerability affects the Windows Interactive Service component of OpenVPN, allowing local authenticated users to cause memory corruption or information disclosure. Red Hat's OpenVPN packages, available in Community Projects like Fedora and EPEL, are Linux-based and do not include the vulnerable Windows-specific service, thus are not directly impacted by this flaw.
    </Statement>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-78221
https://nvd.nist.gov/vuln/detail/CVE-2026-78221
https://community.openvpn.net/Security%20Announcements/CVE-2026-78221
    </References>
</Vulnerability>