CVE-2026-12996: Use After Free
A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7alpha1 through 2.7.4 allows remote authenticated peers to potentially cause a denial of service or leak memory via crafted packets during TLS session promotion or expiry
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/openvpnto a version that resolves this vulnerability.Fixed in 2.6.14-0+deb12u2Fixed in 2.6.14-1+deb13u3Fixed in 2.7.5-1 - Upgrade
Upgrade
OpenVPNto a version that resolves this vulnerability.Fixed in 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12996?
CVE-2026-12996 has a risk rating of 33, indicating a moderate level of severity.
How do I fix CVE-2026-12996?
To mitigate CVE-2026-12996, upgrade OpenVPN to version 2.6.21 or later or apply any available patches.
What versions of OpenVPN are affected by CVE-2026-12996?
CVE-2026-12996 affects OpenVPN versions 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4.
What is the impact of CVE-2026-12996?
CVE-2026-12996 allows remote authenticated peers to cause denial of service or potentially leak memory.
Is CVE-2026-12996 a Use After Free vulnerability?
Yes, CVE-2026-12996 is categorized as a Use After Free vulnerability.