
Latest CVE assigned to trace37. OpenVPN - A use-after-free in OpenVPN's tls-crypt-v2. The safety check meant to stop the server sending a client freed memory has a blind spot, so during a routine key renegotiation OpenVPN frees a buffer it's about to send — and hands whatever now sits in that memory to the client. Remediated by maintainer in version 2.7.5. https://labs.trace37.com/cves/cve-2026-13117/
Post summary
Trace37 reports a use‑after‑free flaw in OpenVPN's tls‑crypt‑v2, fixed in OpenVPN 2.7.5.


