Back

LOW

OpenVPN: OpenVPN: Local denial of service vulnerability in interactive service agent

Published Dec 3, 2025

Description

Interactive service agent in OpenVPN version 2.5.0 through 2.6.16 and 2.7_alpha1 through 2.7_rc2 on Windows allows a local authenticated user to connect to the service and trigger an error causing a local denial of service.

Affected products

Remediation

Red Hat statement

This vulnerability is rated Low for Red Hat. The flaw affects the interactive service agent in OpenVPN on Windows, allowing a local authenticated user to trigger a denial of service. Red Hat's OpenVPN packages are typically deployed on Linux systems and do not include the Windows-specific interactive service agent, therefore No Red Hat products or offerings are affected by this vulnerability.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Metrics

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner OpenVPN
Published Dec 3, 2025
Updated Dec 12, 2025
Reserved Nov 26, 2025
CISA Vulnrichment
Updated Dec 3, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Dec 3, 2025