CVE-2026-81738

Public on 2026-09-05
Modified on 2026-09-05
Description
OpenVPN on Windows contains an off-by-one error in the write_dhcp_search_str() function used to build DHCP options for the Windows TUN/TAP adapter (the DHCP masquerade path). The bounds check for the temporary buffer accounted for one fewer byte per DHCP DOMAIN-SEARCH entry than is actually written, so a set of DHCP options -- which can be pushed by an OpenVPN server -- whose accumulated length lands exactly on the buffer boundary triggers a single-byte overflow of a stack temporary buffer. This issue only affects OpenVPN on Windows and was fixed in OpenVPN 2.7.7 and corresponding 2.6.x updates.
Severity
Medium severity
Medium
See what this means
CVSS v3 Base Score
5.4
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2023 openvpn Not Affected
Amazon Linux 2027 Preview openvpn Not Affected

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L