Memory disclosure and crash via address-family mismatch
Published Dec 1, 2025 · Updated Dec 1, 2025
Heap buffer over-read in OpenVPN 2.7_alpha1 through 2.7_rc1 allows remote attackers to disclose memory or crash a process via invalid IP addresses. The get_addr_generic function accepts an address result whose family differs from the requested family, then copies it as the requested address type. Network-supplied routes or endpoints reach the parser without authentication; the over-read affects confidentiality or process availability, not data integrity.
Summary
What happened
Heap buffer over-read in OpenVPN 2.7_alpha1 through 2.7_rc1 allows remote attackers to disclose memory or crash a process via invalid IP addresses. The get_addr_generic function accepts an address result whose family differs from the requested family, then copies it as the requested address type. Network-supplied routes or endpoints reach the parser without authentication; the over-read affects confidentiality or process availability, not data integrity.
The record
- CVE
- CVE-2025-12106
- Published
- Dec 1, 2025
- Updated
- Dec 1, 2025
- Vendor
- OpenVPN Inc.
- Product
- OpenVPN
- Classifications
- CWE-126, T1499.004
- Attack vector
- network
- Privileges
- unauthenticated
Timeline
How it unfolded
- Dec 1, 2025CVE publishedPublication date reported by the CVE source.
- Dec 1, 2025Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=2.7_alpha1 <=2.7_rc1
What conditions does exploitation require?
What is affected?
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Public exploit references
No public exploit references are available in this record.
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo