Blame

c4f02d Samuli Seppänen 2025-01-29 08:37:37 1
# CVE-2023-46850: Incorrect use of send buffer can cause memory to be sent to peer
2
686563 Samuli Seppänen 2025-02-27 10:05:08 3
OpenVPN 2.6 from v2.6.0 up to and including v.2.6.6 incorrectly use a send buffer after it has been free()d in some circumstances, causing some free()d memory to be sent to the peer. All configurations using TLS (e.g. not using --secret) are affected by this issue.
c4f02d Samuli Seppänen 2025-01-29 08:37:37 4
5
This issue is resolved in OpenVPN 2.6.7.
6
6ccea2 novaflash 2025-07-02 16:27:46 7
MITRE entry: Recent releases (2.2 and later)CVE-2023-46850