Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-78221

Опубликовано: 07 сент. 2026
Источник: redhat
CVSS3: 7.5

Описание

An incorrect buffer size calculation in the Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to cause memory corruption or disclose sensitive information via crafted NRPT inputs.

A flaw was found in OpenVPN. An incorrect buffer size calculation within the Windows Interactive Service allows local authenticated users to trigger memory corruption or disclose sensitive information. This vulnerability can be exploited by providing specially crafted inputs.

Отчет

Important: This vulnerability affects the Windows Interactive Service component of OpenVPN, allowing local authenticated users to cause memory corruption or information disclosure. Red Hat's OpenVPN packages, available in Community Projects like Fedora and EPEL, are Linux-based and do not include the vulnerable Windows-specific service, thus are not directly impacted by this flaw.

Дополнительная информация

Статус:

Important
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2529297OpenVPN: OpenVPN: Memory corruption and information disclosure vulnerability

7.5 High

CVSS3

Связанные уязвимости

ubuntu
10 дней назад

An incorrect buffer size calculation in the Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to cause memory corruption or disclose sensitive information via crafted NRPT inputs.

nvd
10 дней назад

An incorrect buffer size calculation in the Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to cause memory corruption or disclose sensitive information via crafted NRPT inputs.

debian
10 дней назад

An incorrect buffer size calculation in the Windows Interactive Servic ...

github
10 дней назад

An incorrect buffer size calculation in the Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to cause memory corruption or disclose sensitive information via crafted NRPT inputs.

7.5 High

CVSS3