USN-8852-1: OpenVPN vulnerabilities
Ubuntu warns OpenVPN flaws could allow remote code execution or denial of service.
Ubuntu published USN-8852-1 for two OpenVPN vulnerabilities. CVE-2026-84471 is a use-after-free in TLS session handling that could crash OpenVPN or allow arbitrary code execution. CVE-2026-84732 is an integer overflow triggered by retransmitted ACK packet IDs that a remote attacker could use for denial of service. The notice does not say either flaw is being exploited.
- CVE-2026-84471: TLS use-after-free may crash OpenVPN or run code.
- CVE-2026-84732: ACK retransmission overflow can cause denial of service.
- Ubuntu advisory USN-8852-1 reports no in-the-wild exploitation.
Vulnerabilities mentionedAll →
- published —
- CVE-2026-847328.7<1%Unauthenticated denial of service in OpenVPN 2.6/2.7 via ACK packet-ID integer overflowpublished · OpenVPN (OpenVPN project / security@openvpn.net) OpenVPN VPN server/client
| CVE | Vulnerability | CVSS | EPSS | Flags |
|---|
It was discovered that OpenVPN had a use-after-free vulnerability in its TLS session handling. An attacker could possibly use this issue to cause OpenVPN to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-84471) It was discovered that OpenVPN incorrectly handled retransmissions of ACK packet IDs, which could trigger a timeout integer overflow. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2026-84732)
This source does not provide full text. Read it at ubuntu.com.