Bug 2509514 (CVE-2026-13379)
| Summary: | CVE-2026-13379 OpenVPN: OpenVPN: Remote attackers can cause DNS state pollution or service crash via crafted search domain. | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | Keywords: | Security |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in the Windows interactive service of OpenVPN. A remote attacker can exploit this vulnerability by sending a specially crafted search domain during the disconnection process. This can lead to persistent DNS (Domain Name System) state pollution, which may disrupt network services, or cause the OpenVPN service to crash, resulting in a denial of service.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2509670, 2509671 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-07-30 17:01:35 UTC
|