An incorrect buffer size calculation in the Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to cause memory corruption or disclose sensitive information via crafted NRPT inputs.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 07 Sep 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Memory Corruption and Sensitive Information Disclosure via Crafted NRPT Inputs in Windows Interactive Service | |
| First Time appeared |
Openvpn
Openvpn openvpn |
|
| Vendors & Products |
Openvpn
Openvpn openvpn |
Mon, 07 Sep 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An incorrect buffer size calculation in the Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to cause memory corruption or disclose sensitive information via crafted NRPT inputs. | |
| Weaknesses | CWE-131 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: OpenVPN
Published:
Updated: 2026-09-07T07:28:14.135Z
Reserved: 2026-08-26T14:41:20.459Z
Link: CVE-2026-78221
No data.
Status : Received
Published: 2026-09-07T08:17:12.813
Modified: 2026-09-07T08:17:12.813
Link: CVE-2026-78221
No data.
OpenCVE Enrichment
Updated: 2026-09-07T08:30:14Z
Weaknesses