Use-after-free in OpenVPN Server - CVE-2026-12996
Published: July 2, 2026 / Updated: July 28, 2026
OpenVPN Server
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use-after-free in ack_write_buf() when processing a well-timed sequence of control channel and authentication packets. A remote attacker can send a specially crafted packet sequence to cause a denial of service.