Blame
| 60613e | flichtenheld | 2026-07-08 14:14:50 | 1 | # CVE-2026-13698 - Server memory leak via repeated tls-crypt-v2 HARD_RESET_CLIENT_V3 packets |
| 080b98 | David Sommerseth | 2026-06-29 12:13:55 | 2 | |
| 43a414 | flichtenheld | 2026-07-23 15:13:23 | 3 | A memory leak in the `tls_crypt_v2_extract_client_key` function in OpenVPN 2.x allows remote attackers with a valid |
| 4 | tls-crypt-v2 client key to cause a denial of service (memory exhaustion) via repeated `HARD_RESET_CLIENT_V3` packets |
|||
| 5 | when `tls-crypt-v2` is enabled because the server fails to free existing key contexts before overwriting them during |
|||
| 6 | session re-initialisation. |
|||
| 7 | ||||
| 8 | OpenVPN version 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 are affected. This is fixed in versions 2.6.21 and 2.7.5. |
|||
| 60613e | flichtenheld | 2026-07-08 14:14:50 | 9 | |
| 10 | CVE Record: [CVE-2026-13698](https://www.cve.org/CVERecord?id=CVE-2026-13698) |
|||
| 11 | ||||
| 12 | Github: |
|||
| 13 | * [OpenVPN/openvpn-private-issues#137](https://github.com/OpenVPN/openvpn-private-issues/issues/137) |
|||
| 14 | ||||
| 15 | Release notes: |
|||
| 16 | * [openvpn-2.7.5](https://community.openvpn.net/ReleaseHistory#openvpn-275-released-1-july-2026) |
|||
| 17 | * [openvpn-2.6.21](https://community.openvpn.net/ReleaseHistory#openvpn-2621-released-1-july-2026) |
|||
| 18 | ||||
| 19 | Reported-By: Max Fillinger (maximilian.fillinger@sentyron.com) |
