Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-81738

Опубликовано: 07 сент. 2026
Источник: redhat
CVSS3: 4.2

Описание

OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-bounds write via crafted DOMAIN-SEARCH entries

A flaw was found in OpenVPN when using the tap-windows6 driver. A remote attacker could exploit this vulnerability by sending specially crafted DOMAIN-SEARCH entries. This could lead to an out-of-bounds write, potentially causing information disclosure or a denial of service.

Отчет

This Low impact vulnerability in OpenVPN affects Windows installations utilizing the tap-windows6 driver. Red Hat products are not directly impacted as they do not deploy OpenVPN with this specific Windows driver.

Дополнительная информация

Статус:

Low
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2529301openvpn: OpenVPN: Out-of-bounds write via crafted DOMAIN-SEARCH entries

4.2 Medium

CVSS3

Связанные уязвимости

ubuntu
13 дней назад

OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-bounds write via crafted DOMAIN-SEARCH entries

nvd
9 дней назад

OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-bounds write via crafted DOMAIN-SEARCH entries

debian
9 дней назад

OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver a ...

github
9 дней назад

OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-bounds write via crafted DOMAIN-SEARCH entries

4.2 Medium

CVSS3