What is CVE-2026-13117?
CVE-2026-13117 describes a use-after-free vulnerability in OpenVPN versions 2.6.0-2.6.20 and 2.7_alpha1-2.7.4 during TLS session promotion. This can allow remote authenticated peers to trigger a denial of service or memory leakage, necessitating an immediate update.
Azərbaycanca: CVE-2026-13117 identifikatoru OpenVPN-in 2.6.0-2.6.20 və 2.7_alpha1-2.7.4 versiyalarında TLS sessiya yüksəldilməsi zamanı istifadə-sonrası-sərbəst buraxma (use-after-free) zəifliyini təsvir edir. Bu, autentifikasiya olunmuş uzaq istifadəçilərə xidmət dayandırılması (DoS) və ya yaddaş sızması yaratmağa imkan verə bilər, buna görə OpenVPN yeniləmələrinin təcili tətbiq edilməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-416
FAQ2
Which OpenVPN versions are affected by CVE-2026-13117?
CVE-2026-13117 affects OpenVPN versions from 2.6.0 to 2.6.20, as well as versions 2.7_alpha1 to 2.7.4.
What are the potential impacts of exploiting CVE-2026-13117?
This use-after-free vulnerability can allow authenticated remote peers to trigger a denial of service (DoS) or cause memory leakage.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.