CVE Vulnerabilities

CVE-2025-12106

Buffer Over-read

Published: Dec 01, 2025 | Modified: Dec 30, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Insufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an attacker to trigger a heap buffer over-read when parsing IP addresses

Weakness

The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.

Affected Software

NameVendorStart VersionEnd Version
OpenvpnOpenvpn2.6.13 (including)2.6.13 (including)
OpenvpnOpenvpn2.7-alpha1 (including)2.7-alpha1 (including)
OpenvpnOpenvpn2.7-alpha2 (including)2.7-alpha2 (including)
OpenvpnOpenvpn2.7-alpha3 (including)2.7-alpha3 (including)
OpenvpnOpenvpn2.7-beta1 (including)2.7-beta1 (including)
OpenvpnOpenvpn2.7-beta2 (including)2.7-beta2 (including)
OpenvpnOpenvpn2.7-beta3 (including)2.7-beta3 (including)
OpenvpnOpenvpn2.7-rc1 (including)2.7-rc1 (including)

References