CVE-2023-46850: Incorrect use of send buffer can cause memory to be sent to peer

OpenVPN 2.6 from version 2.6.0 up to and including 2.6.6 incorrectly uses a send buffer after it has been freed in some circumstances. This error causes some freed memory to be sent to the peer. All configurations using TLS (i.e., not using --secret) are affected by this issue.

This issue is resolved in OpenVPN 2.6.7.

MITRE entry: CVE-2023-46850

0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9