CVE-2023-46850: Debian Linux
Critical severity, CVSS 9.8. EPSS: 2% chance of exploitation in the next 30 days.
Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending network buffers to a remote peer.
Affected products
- Debian Debian Linux: version 12.0 only
- Fedoraproject Fedora: version 39 only
- Openvpn Openvpn: from 2.6.0, up to and including 2.6.6
- Openvpn Openvpn Access Server: from 2.11.0, up to and including 2.11.3; from 2.12.0, before 2.12.2 (fixed in 2.12.2)
Published 2023-11-11. Last modified 2026-06-23.