Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-84732

Опубликовано: 07 сент. 2026
Источник: redhat
CVSS3: 7.5

Описание

Retransmissions of ACK packet ID in OpenVPN through 2.6.22 and 2.7.6 allow remote unauthenticated attackers to cause a denial of service via crafted inputs that trigger a timeout integer overflow

A flaw was found in OpenVPN. Remote unauthenticated attackers can cause a denial of service by sending specially crafted network inputs. These inputs trigger a timeout integer overflow during the retransmission of acknowledgment (ACK) packet IDs, which can make the OpenVPN service unavailable.

Отчет

This is an Important denial of service flaw in OpenVPN, enabling remote unauthenticated attackers to disrupt service availability. The vulnerability, stemming from crafted ACK packet retransmissions, can render OpenVPN instances unresponsive when exposed to untrusted networks, posing a significant risk to VPN service continuity.

Дополнительная информация

Статус:

Important
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2529320openvpn: OpenVPN: Remote Denial of Service via crafted ACK packets

7.5 High

CVSS3

Связанные уязвимости

ubuntu
12 дней назад

Retransmissions of ACK packet ID in OpenVPN through 2.6.22 and 2.7.6 allow remote unauthenticated attackers to cause a denial of service via crafted inputs that trigger a timeout integer overflow

nvd
9 дней назад

Retransmissions of ACK packet ID in OpenVPN through 2.6.22 and 2.7.6 allow remote unauthenticated attackers to cause a denial of service via crafted inputs that trigger a timeout integer overflow

debian
9 дней назад

Retransmissions of ACK packet ID in OpenVPN through 2.6.22 and 2.7.6 a ...

github
9 дней назад

Retransmissions of ACK packet ID in OpenVPN through 2.6.22 and 2.7.6 allow remote unauthenticated attackers to cause a denial of service via crafted inputs that trigger a timeout integer overflow

7.5 High

CVSS3