CVE-2026-78221
5.9
CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:P/VC:H/VI:N/VA:H/SC:H/SI:N/SA:H
Summary
An incorrect buffer size calculation in the Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to cause memory corruption or disclose sensitive information via crafted NRPT inputs.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| OpenVPN | OpenVPN | 2.7_alpha1 <= 2.7.6 | affected |
Weaknesses
- CWE-131: CWE-131 Incorrect calculation of buffer size
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.