CVE-2026-12932

Description

A flaw was found in OpenVPN. A memory leak in the tls-crypt-v2 client key extraction allows remote attackers to cause a denial of service (DoS). By sending a flood of specially crafted packets, an attacker can exhaust the system's memory, making the service unavailable.

Statement

This vulnerability is rated as Important. A memory leak within the tls-crypt-v2 client key extraction mechanism of OpenVPN can be remotely triggered by an unauthenticated attacker. By sending a high volume of specially crafted packets, an attacker can exhaust system memory, leading to a denial of service for the OpenVPN service. This impact is significant due to the remote, unauthenticated nature of the attack.

Understanding the Weakness (CWE)

Availability

Technical Impact: DoS: Resource Consumption (Other)

An attacker that can influence the allocation of resources that are not properly maintained could deplete the available resource pool and prevent all other processes from accessing the same type of resource.

Frequently Asked Questions

Want to get errata notifications? Sign up here.