PT-2024-5857 · Openvpn+7 · Openvpn+7

Reynir Björnsson

·

Published

2024-05-14

·

Updated

2025-08-31

·

CVE-2024-5594

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions OpenVPN versions prior to 2.6.11
Description The issue is related to the lack of proper sanitization of PUSH REPLY messages, which can be exploited by attackers to inject unexpected arbitrary data into third-party executables or plug-ins. This can potentially impact the confidentiality, integrity, and availability of protected information. A malicious OpenVPN peer can send garbage to the OpenVPN log or cause a high CPU load by sending control channel messages with nonprintable characters.
Recommendations For OpenVPN versions prior to 2.6.11, update to version 2.6.11 or later to eliminate the risk. As a temporary workaround, consider refusing control channel messages with nonprintable characters in them to minimize the risk of exploitation. Restrict access to the control channel to prevent malicious OpenVPN peers from sending garbage to the log or causing high CPU load. Avoid using the PUSH REPLY message until the issue is resolved.

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-10642
ALT-PU-2024-10859
ALT-PU-2024-10885
BDU:2024-06604
BDU:2025-03850
CVE-2024-5594
DLA-4079-1
DLA-4079-2
MGASA-2024-0255
OESA-2024-1885
OPENSUSE-SU-2025:14707-1
OPENSUSE-SU-2025_0278-1
OPENSUSE-SU-2025_1131-1
SUSE-SU-2025:0278-1
SUSE-SU-2025:1053-1
SUSE-SU-2025:1053-2
SUSE-SU-2025:1131-1
SUSE-SU-2025_0278-1
SUSE-SU-2025_1053-1
SUSE-SU-2025_1053-2
SUSE-SU-2025_1131-1
USN-6860-1
USN-7340-1

Affected Products

Alt Linux
Astra Linux
Debian
Linuxmint
Openvpn
Red Os
Suse
Ubuntu