CVE-2026-81738
Public on 2026-09-05
Modified on 2026-09-05
Description
OpenVPN on Windows contains an off-by-one error in the write_dhcp_search_str() function used to build DHCP options for the Windows TUN/TAP adapter (the DHCP masquerade path). The bounds check for the temporary buffer accounted for one fewer byte per DHCP DOMAIN-SEARCH entry than is actually written, so a set of DHCP options -- which can be pushed by an OpenVPN server -- whose accumulated length lands exactly on the buffer boundary triggers a single-byte overflow of a stack temporary buffer. This issue only affects OpenVPN on Windows and was fixed in OpenVPN 2.7.7 and corresponding 2.6.x updates.
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
| Platform | Package | Release Date | Advisory | Status |
|---|---|---|---|---|
| Amazon Linux 2023 | openvpn | Not Affected | ||
| Amazon Linux 2027 Preview | openvpn | Not Affected |
CVSS Scores
| Score Type | Score | Vector | |
|---|---|---|---|
| Amazon Linux | CVSSv3 | 5.4 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L |