Home

Description

OpenVPN from 2.6.0 through 2.6.10 in a server role accepts multiple exit notifications from authenticated clients which will extend the validity of a closing session

PUBLISHED Reserved 2024-03-12 | Published 2024-07-08 | Updated 2024-11-01 | Assigner OpenVPN

Problem types

Missing Release of Resource after Effective Lifetime

Product status

Default status
unaffected

2.6.0 (patch)
affected

References

community.openvpn.net/openvpn/wiki/CVE-2024-28882

www.mail-archive.com/...@lists.sourceforge.net/msg07634.html

cve.org (CVE-2024-28882)

nvd.nist.gov (CVE-2024-28882)

Download JSON