CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

USN-8540-1: OpenVPN vulnerabilities

unknownCVE-2026-11771CVE-2026-12932CVE-2026-12996CVE-2026-13117CVE-2026-13122CVE-2026-13698
It was discovered that OpenVPN had a 1-byte buffer overrun when handling NTLMv2 proxy responses. An attacker could use this issue to cause a denial of service or possibly execute arbitrary code. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-11771) It was discovered that OpenVPN incorrectly handled metadata when extracting tls-crypt-v2 client keys. An attacker could possibly use this issue to obtain sensitive information. (CVE-2026-12932) It was discovered that OpenVPN had a use-after-free in the ack_write_buf handling. An attacker could use this issue to cause OpenVPN to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2026-12996) It was discovered that OpenVPN had a use-after-free in the tls_wrap_reneg handling. An attacker could use this issue to cause OpenVPN to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-13117) It was discovered that OpenVPN incorrectly validated authentication tokens when external authentication was enabled. A remote attacker could possibly use this issue to cause OpenVPN to crash, resulting in a denial of service. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-13122) It was discovered that OpenVPN had a memory leak when handling tls-crypt-v2 client keys. A remote attacker with a valid tls-crypt-v2 client key could possibly use this issue to cause OpenVPN to consume excessive resources, leading to a denial of service. (CVE-2026-13698)

CSIRTS triage

vendor: OpenVPNproduct: OpenVPNDenial of serviceOtheraffected: Ubuntu 24.04 LTS and Ubuntu 26.04 LTS
What
Multiple vulnerabilities could lead to denial of service or arbitrary code execution.
Who is affected
Users of OpenVPN on Ubuntu 24.04 LTS and 26.04 LTS.
Urgency
Remediation is necessary due to the potential for denial of service and code execution, though not currently exploited.
Action
Apply the latest updates for OpenVPN.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch OpenVPN

Get an email when a new OpenVPN advisory drops — max one per day, one-click unsubscribe.

Details

Source
Ubuntu Security Notices (INTL · vendor-psirt · site)
Severity
unknown
Published
2026-07-14
Exploitation
Not in CISA KEV at last sync

Original advisory: https://ubuntu.com/security/notices/USN-8540-1

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-11771coverage & exploitation statusNVD · CVE.org
CVE-2026-12932coverage & exploitation statusNVD · CVE.org
CVE-2026-12996coverage & exploitation statusNVD · CVE.org
CVE-2026-13117coverage & exploitation statusNVD · CVE.org
CVE-2026-13122coverage & exploitation statusNVD · CVE.org
CVE-2026-13698coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from Ubuntu Security Notices