CVE-2025-12106 Details
Description
Insufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an attacker to trigger a heap buffer over-read when parsing IP addresses
A heap buffer over-read vulnerability has been identified in OpenVPN versions 2.7_alpha1 through 2.7_rc1. This issue arises from insufficient validation of arguments when parsing IP addresses, allowing an attacker to exploit the vulnerability.
Users can upgrade to OpenVPN 2.7_rc2, which addresses this vulnerability by fixing the buffer over-read issue in IPv6 address parsing. This version is available for download from the OpenVPN community downloads page. Additionally, packages for Debian, Ubuntu, Fedora, RHEL, and openSUSE can be obtained from the official OpenVPN community repositories.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 1, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://community.openvpn.net/Security%20Announcements/CVE-2025-12106 | [email protected] | Vendor Advisory |
| https://www.mail-archive.com/[email protected]/msg00152.html | [email protected] | Mailing List |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-126 | Buffer Over-read | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| openvpn openvpn | 2.6.13 2.7 alpha1 2.7 alpha2 2.7 alpha3 2.7 beta1 2.7 beta2 2.7 beta3 2.7 rc1 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 26, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 30, 2025 | Initial Analysis | [email protected] |
| Dec 1, 2025 | CVE Modified | CISA-ADP |
| Dec 1, 2025 | New CVE Received | [email protected] |