Junglewise Threat Intelligence

CVE-2026-40215: OpenVPN race condition and use-after-free in TLS session promotion

CVE-2026-40215 · Severity: info · CVSS 6.1 · Published 2026-06-08

Technologies: OpenVPN Inc. Openvpn.

Executive brief

OpenVPN, a widely used software for creating secure private networks, contains a vulnerability that could allow an attacker to crash the server or access sensitive memory. This issue occurs during the process of establishing a secure connection, potentially leading to service outages or the exposure of internal system data. Organizations using affected versions should update to OpenVPN 2.6.20 or 2.7.2 to maintain service availability and data confidentiality.

Technical details

A race condition exists in OpenVPN versions 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 during the TLS session promotion phase. This flaw can lead to a use-after-free (CWE-416) or an out-of-bounds read (CWE-125). A remote attacker with low privileges (PR:L) can exploit this over the network to trigger a denial-of-service (server crash) or leak sensitive information from the heap memory. The vulnerability is addressed in OpenVPN versions 2.6.20 and 2.7.2.

Affected products

  • OpenVPN Inc. OpenVPN 2.6.0 through 2.6.19, 2.7_alpha1 through 2.7.1

Timeline

  • 2026-04-22: patched: OpenVPN 2.6.20 and 2.7.2 released to address the issue.
  • 2026-06-08: disclosed: CVE-2026-40215 published.

References