CVE-2025-12106
01.12.2025, 13:16
Insufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an attacker to trigger a heap buffer over-read when parsing IP addressesEnginsight
| Vendor | Product | Version |
|---|---|---|
| openvpn | openvpn | 2.6.13 |
| openvpn | openvpn | 2.7:alpha1 |
| openvpn | openvpn | 2.7:alpha2 |
| openvpn | openvpn | 2.7:alpha3 |
| openvpn | openvpn | 2.7:beta1 |
| openvpn | openvpn | 2.7:beta2 |
| openvpn | openvpn | 2.7:beta3 |
| openvpn | openvpn | 2.7:rc1 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration