Bugzilla – Bug 1227545
VUL-0: CVE-2024-1305: openvpn: tap-windows6: potential integer overflow in TapSharedSendPacket
Last modified: 2024-07-09 08:42:53 UTC
tap-windows6 driver version 9.26 and earlier does not properly check the size data of incomming write operations which an attacker can use to overflow memory buffers, resulting in a bug check and potentially arbitrary code execution in kernel space References: https://www.mail-archive.com/openvpn-users@lists.sourceforge.net/msg07534.html http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-1305 https://www.cve.org/CVERecord?id=CVE-2024-1305 https://community.openvpn.net/openvpn/wiki/CVE-2024-1305
Closing since are related to windows drivers.