Unauthenticated denial of service in OpenVPN 2.6/2.7 via ACK packet-ID integer overflow
AI analysis
OpenVPN versions through 2.6.22 and through 2.7.6 contain an integer overflow (CWE-190) in the retransmission handling of ACK packet IDs, which can cause a timeout value to wrap. A remote, unauthenticated attacker who can reach a listening OpenVPN service can send crafted inputs that trigger the overflow, causing the service to time out or fail and disrupting VPN connectivity. The impact is availability-only; the CVSS 4.0 vector shows no confidentiality or integrity impact to the tunnel or data. All deployments running affected 2.6.x releases up to and including 2.6.22, or 2.7.x releases up to and including 2.7.6, are potentially exposed. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and EPSS estimates only a 0.5% probability of exploitation in the next 30 days.
What to do: Upgrade OpenVPN servers and clients to a fixed 2.6-series release newer than 2.6.22 or a fixed 2.7-series release newer than 2.7.6, per the OpenVPN security advisory (AV26-889). Until patched, restrict exposure of OpenVPN service ports to trusted source networks and monitor for unexpected process crashes or restarts. Operators of third-party products (appliances, router firmware) that bundle affected OpenVPN versions should apply vendor updates when they ship fixes.
Affected
| OpenVPN (OpenVPN project / [email protected]) OpenVPN VPN server/client | 2.6.x through and including 2.6.22 |
| OpenVPN (OpenVPN project / [email protected]) OpenVPN VPN server/client | 2.7.x through and including 2.7.6 |
Estimated exposure
masslikely millions of installations (OpenVPN is among the most widely deployed open-source VPNs, with on the order of hundreds of thousands of OpenVPN services… — OpenVPN is embedded across enterprise VPN gateways, cloud images, and consumer/prosumer router firmware, and public internet scans have historically indexed hundreds of thousands of OpenVPN services, so the population of affected installs…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.