CVE-2026-88964

Public on 2026-10-09
Modified on 2026-10-09
Description
domain_search_list_len is unsigned, and the post-decrement runs on the final test too. When the length reaches 0 the condition is false but the decrement has already wrapped it to UINT_MAX, so the field is left corrupted. The next reset then does

o->domain_search_list[UINT_MAX] = NULL

and walks far out of bounds, writing NULL through each slot. A server can drive this reset path against a client with PUSH_UPDATE, so on Windows and Android this is a remotely reachable out-of-bounds write.

NOTE: Fixed by: https://github.com/OpenVPN/openvpn/commit/d586f8ad9bfc582cc7984fcd482dc7cfacc940e2 (v2.7.8)
Severity
Medium severity
Medium
See what this means
CVSS v3 Base Score
6.5
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2023 openvpn Not Affected
Amazon Linux 2027 Preview openvpn Pending Fix

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H