Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-12932

Опубликовано: 30 июл. 2026
Источник: debian
EPSS Низкий

Описание

A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service (memory exhaustion) via a flood of crafted packets

Пакеты

ПакетСтатусВерсия исправленияРелизТип
openvpnfixed2.7.5-1package

Примечания

  • Fixed by: https://github.com/OpenVPN/openvpn/commit/19c9ad5bb75942f66608d2ae28c0614a0a5c6073 (v2.7.5)

EPSS

Процентиль: 35%
0.00417
Низкий

Связанные уязвимости

CVSS3: 8.1
ubuntu
19 дней назад

A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service (memory exhaustion) via a flood of crafted packets

CVSS3: 7.5
redhat
19 дней назад

A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service (memory exhaustion) via a flood of crafted packets

CVSS3: 8.1
nvd
19 дней назад

A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service (memory exhaustion) via a flood of crafted packets

CVSS3: 8.1
github
19 дней назад

A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service (memory exhaustion) via a flood of crafted packets

suse-cvrf
7 дней назад

Security update for openvpn

EPSS

Процентиль: 35%
0.00417
Низкий