Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 40: FEDORA-2024-b611e122fb Critical: OpenVPN Control Issues

fedora
Calendar Grey June 27, 2024
Dist Fedora Esm H88
The recent OpenVPN 2.6.11 upgrade in Fedora 40 tackles significant flaws, bolstering defenses against vulnerabilities linked to control channel communications.
Update to upstream OpenVPN 2.6.11 CVE-2024-5594: control channel: refuse control channel messages with nonprintable characters in them CVE-2024-28882: only call schedule_exit() onc...

Summary

OpenVPN is a robust and highly flexible tunneling application that uses all

of the encryption, authentication, and certification features of the

OpenSSL library to securely tunnel IP networks over a single UDP or TCP

port. It can use the Marcus Franz Xaver Johannes Oberhumers LZO library

for compression.

Update Information:

Update to upstream OpenVPN 2.6.11 CVE-2024-5594: control channel: refuse control channel messages with nonprintable characters in them CVE-2024-28882: only call schedule_exit() once (on a given peer)

Change Log

* Fri Jun 21 2024 Frank Lichtenheld - 2.6.11-1 - Update to upstream OpenVPN 2.6.11 - Remove obsolete "beta release" qualifier from Summary

References


[ 1 ] Bug #2270512 - openvpn-2.6.11 is available https://bugzilla.redhat.com/show_bug.cgi?id=2270512

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-b611e122fb' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: openvpn
Product: Fedora 40
Version: 2.6.11
Release: 1.fc40
URL: /
Summary: A full-featured TLS VPN solution

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here