Two security vulnerabilities were discovered in OpenVPN, which could result in denial of service or a leak of packet data from a previous handshake. For the oldstable distribution (bookworm), these problems have been fixed in version 2.6.14-0+deb12u1.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6289-1
MGASA-2026-0126 - Updated openvpn packages fix security vulnerabilities. MGASA-2026-0126 - Updated openvpn packages fix security vulnerabilities Publication date: 10 May 2026 URL: https://advisories.mageia.org/MGASA-2026-0126.html Type: security Affected Mageia releases: 9 CVE: CVE-2026-35058, CVE-2026-40215 Description: CVE-2026-35058 - fix server ASSERT() on receiving a suitably malformed packet with a valid tls-crypt-v2 key CVE-2026-40215 - fix race condition in TLS handshake that could lead to leaking of packet data from a previous handshake under specific circumstances References: - https://bugs.mageia.org/show_bug.cgi?id=35442 - https://lists.fedoraproject.org/archives/list/
Get the latest Linux and open source security news straight to your inbox.