PT-2026-36645 · Openvpn+2 · Openvpn+2

CVE-2026-40215

·

Published

2026-04-23

·

Updated

2026-08-12

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenVPN versions 2.6.0 through 2.6.19 OpenVPN versions 2.7 alpha1 through 2.7.1
Description A race condition occurs during the TLS handshake, specifically during TLS session promotion. This issue can be triggered by remote attackers, potentially leading to a server crash or the leaking of heap memory, which may include packet data from a previous handshake. A race condition is a situation where the system's substantive behavior is dependent on the sequence or timing of other uncontrollable events.
Recommendations Update OpenVPN versions 2.6.0 through 2.6.19 to a version where this issue is resolved. Update OpenVPN versions 2.7 alpha1 through 2.7.1 to a version where this issue is resolved.

Exploit

Fix

Out of bounds Read

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40215
MGASA-2026-0126
OESA-2026-2623
OESA-2026-2624
OESA-2026-2625
OESA-2026-2626
SUSE-SU-2026:3596-1
USN-8286-1

Affected Products

Linuxmint
Openvpn
Ubuntu