CVE-2026-88964 - Unsigned underflow and OOB access on malicious PUSH_UPDATE from server

An integer underflow in OpenVPN on Windows and Android allows remote authenticated servers to cause a denial of service or memory disclosure via crafted domain search options.

OpenVPN versions 2.7_alpha3 through 2.7.7 are affected. This is fixed in version 2.7.8.

CVE Record: CVE-2026-88964

Github:

Release notes:

Reported-By: Cole Munz

0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9