Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3mmv-h5fc-pvwj

Опубликовано: 08 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.1
CVSS3: 7.4

Описание

A race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows remote attackers to potentially cause a server crash or leak heap memory via a use-after-free triggered during TLS session promotion.

A race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows remote attackers to potentially cause a server crash or leak heap memory via a use-after-free triggered during TLS session promotion.

EPSS

Процентиль: 31%
0.00372
Низкий

6.1 Medium

CVSS4

7.4 High

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 7.4
ubuntu
4 месяца назад

A race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows remote attackers to potentially cause a server crash or leak heap memory via a use-after-free triggered during TLS session promotion.

CVSS3: 6.5
redhat
4 месяца назад

A race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows remote attackers to potentially cause a server crash or leak heap memory via a use-after-free triggered during TLS session promotion.

CVSS3: 7.4
nvd
4 месяца назад

A race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows remote attackers to potentially cause a server crash or leak heap memory via a use-after-free triggered during TLS session promotion.

CVSS3: 7.4
debian
4 месяца назад

A race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 throug ...

suse-cvrf
около 1 месяца назад

Security update for openvpn

EPSS

Процентиль: 31%
0.00372
Низкий

6.1 Medium

CVSS4

7.4 High

CVSS3

Дефекты

CWE-125