Blame
| df894b | uddr | 2026-09-03 15:52:11 | 1 | # CVE-2026-84732 - Reliability layer unbounded TLS timeout and acks for non-outstanding packets |
| 2 | ||||
| 3 | OpenVPN 2.x allows attackers to potentially cause a denial of service against the control channel reliability layer, either by driving the reliable TLS retransmission timeout to grow without bound, or by sending acknowledgements for packets that cannot be outstanding. |
|||
| 4 | ||||
| 5 | OpenVPN version 2.6.22 and 2.7.6 are affected. This is fixed in version 2.7.7. |
|||
| 6 | ||||
| 7 | CVE Record: [CVE-2026-84732](https://www.cve.org/CVERecord?id=CVE-2026-84732) |
|||
| 8 | ||||
| 9 | Github: |
|||
| 10 | * [OpenVPN/openvpn-private-issues#161](https://github.com/OpenVPN/openvpn-private-issues/issues/161) |
|||
| 11 | ||||
| 12 | Release notes: |
|||
| 13 | * [openvpn-2.7.7](https://community.openvpn.net/ReleaseHistory#openvpn-277-released-3-september-2026) |
|||
| 14 | ||||
| 15 | Reported-By: Mark Bregman (Fox-IT) |
