CVE-2026-84732
8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L
Summary
Retransmissions of ACK packet ID in OpenVPN through 2.6.22 and 2.7.6 allow remote unauthenticated attackers to cause a denial of service via crafted inputs that trigger a timeout integer overflow
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| OpenVPN | OpenVPN | 0 <= 2.6.22 | affected |
| OpenVPN | OpenVPN | 0 <= 2.7.6 | affected |
Weaknesses
- CWE-190: CWE-190 Integer overflow or wraparound
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.