USN-8540-1: OpenVPN vulnerabilities
It was discovered that OpenVPN had a 1-byte buffer overrun when handling NTLMv2 proxy responses. An attacker could use this issue to cause a denial of service or possibly execute arbitrary code. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-11771) It was discovered that OpenVPN incorrectly handled metadata when extracting tls-crypt-v2 client keys. An attacker could possibly use this issue to obtain sensitive information. (CVE-2026-12932) It was discovered that OpenVPN had a use-after-free in the ack_write_buf handling. An attacker could use this issue to cause OpenVPN to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2026-12996) It was discovered that OpenVPN had a use-after-free in the tls_wrap_reneg handling. An attacker could use this issue to cause OpenVPN to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-13117) It was discovered that OpenVPN incorrectly validated authentication tokens when external authentication was enabled. A remote attacker could possibly use this issue to cause OpenVPN to crash, resulting in a denial of service. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-13122) It was discovered that OpenVPN had a memory leak when handling tls-crypt-v2 client keys. A remote attacker with a valid tls-crypt-v2 client key could possibly use this issue to cause OpenVPN to consume excessive resources, leading to a denial of service. (CVE-2026-13698)
CSIRTS triage
- What
- Multiple vulnerabilities could lead to denial of service or arbitrary code execution.
- Who is affected
- Users of OpenVPN on Ubuntu 24.04 LTS and 26.04 LTS.
- Urgency
- Remediation is necessary due to the potential for denial of service and code execution, though not currently exploited.
- Action
- Apply the latest updates for OpenVPN.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch OpenVPN
Get an email when a new OpenVPN advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://ubuntu.com/security/notices/USN-8540-1
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-117710.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all scored CVEs.
- Low exploitation riskCVE-2026-129320.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all scored CVEs.
- Low exploitation riskCVE-2026-129960.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all scored CVEs.
- Low exploitation riskCVE-2026-131170.37% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 29% of all scored CVEs.
- Low exploitation riskCVE-2026-131220.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all scored CVEs.
- Low exploitation riskCVE-2026-136980.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-11771 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-12932 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-12996 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-13117 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-13122 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-13698 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] OpenVPN: Multiple vulnerabilitiescert-bund
- unknownCVE-2026-13117: An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote…nvd
- unknownCVE-2026-12996: A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote au…nvd
- unknownCVE-2026-12932: A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.…nvd
- unknownCVE-2026-11771: OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-…nvd
- mediumCVE-2026-13122: OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to c…nvd
- highCVE-2026-13698: A memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 through 2.6.20 and 2.7_alpha1 thr…nvd
- unknownDSA-6376-1 openvpn - security updatedebian
More from Ubuntu Security Notices
- highUSN-8620-4: Linux kernel (Intel IoTG) vulnerabilities2026-07-31
- highUSN-8620-3: Linux kernel (Intel IoTG) vulnerabilities2026-07-31
- unknownUSN-8625-1: OpenSSL vulnerability2026-07-30
- unknownUSN-8624-1: Sinatra vulnerability2026-07-29
- unknownUSN-8623-1: Linux kernel (NVIDIA) vulnerabilities2026-07-29