CVE-2017-12166: Debian Linux

Critical severity, CVSS 9.8. EPSS: 3.6% chance of exploitation in the next 30 days.

OpenVPN versions before 2.3.3 and 2.4.x before 2.4.4 are vulnerable to a buffer overflow vulnerability when key-method 1 is used, possibly resulting in code execution.

Affected products

  • Debian Debian Linux: version 9.0 only
  • Openvpn Openvpn: before 2.3.18 (fixed in 2.3.18); from 2.4.0, before 2.4.4 (fixed in 2.4.4)

Published 2017-10-04. Last modified 2026-06-17.