Executive brief
OpenVPN is widely used to provide secure remote access and site-to-site network connections. A vulnerability in how OpenVPN handles retransmissions of ACK packets can allow remote attackers to cause the service to crash or become unresponsive, disrupting access for legitimate users without needing to authenticate first.
Technical details
The vulnerability exists in OpenVPN's handling of ACK packet retransmissions, where a timeout integer overflow can be triggered through crafted inputs. An unauthenticated remote attacker can send specially crafted packets over the network to trigger this integer overflow condition, causing a denial of service. The affected versions are OpenVPN 2.6.22 and earlier in the 2.6 series, and 2.7.6 and earlier in the 2.7 series. No patch information is currently available in the advisory.
Affected products
- OpenVPN OpenVPN through 2.6.22 and 2.7.6
Timeline
- 2026-09-07: disclosed