What is CVE-2026-12996?
A use-after-free vulnerability was discovered in OpenVPN versions 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4. This flaw could allow remote authenticated peers to cause denial of service or memory leaks via crafted packets during TLS session promotion. Updating to the latest OpenVPN version is strongly recommended.
Azərbaycanca: OpenVPN-in 2.6.0-2.6.20 və 2.7_alpha1-2.7.4 versiyalarında "use-after-free" zəifliyi aşkar edilib. Bu, autentifikasiya olunmuş uzaq tərəfdaşlara xüsusi hazırlanmış paketlər vasitəsilə xidmət dayanmasına (DoS) və ya yaddaş sızmasına səbəb ola bilər. TLS sessiyasının irəlilədilməsi zamanı yaranır, OpenVPN-in son versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-416
FAQ2
Which versions of OpenVPN are affected by CVE-2026-12996?
This vulnerability affects OpenVPN versions 2.6.0 through 2.6.20, as well as versions 2.7_alpha1 through 2.7.4.
How can the CVE-2026-12996 vulnerability be exploited?
Remote authenticated peers can exploit this use-after-free vulnerability by sending specially crafted packets during TLS session promotion, which may lead to denial of service (DoS) or memory leaks.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.