Ubuntu alert USN-8540-1 (openvpn)
| From: | noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com> | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-8540-1] OpenVPN vulnerabilities | |
| Date: | Tue, 14 Jul 2026 16:30:22 +0000 | |
| Message-ID: | <E1wjg1W-0002j3-VH@lists.ubuntu.com> | |
| Cc: | noreply+usn-bot@canonical.com |
========================================================================== Ubuntu Security Notice USN-8540-1 July 14, 2026 openvpn vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in OpenVPN. Software Description: - openvpn: virtual private network software Details: It was discovered that OpenVPN had a 1-byte buffer overrun when handling NTLMv2 proxy responses. An attacker could use this issue to cause a denial of service or possibly execute arbitrary code. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-11771) It was discovered that OpenVPN incorrectly handled metadata when extracting tls-crypt-v2 client keys. An attacker could possibly use this issue to obtain sensitive information. (CVE-2026-12932) It was discovered that OpenVPN had a use-after-free in the ack_write_buf handling. An attacker could use this issue to cause OpenVPN to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2026-12996) It was discovered that OpenVPN had a use-after-free in the tls_wrap_reneg handling. An attacker could use this issue to cause OpenVPN to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-13117) It was discovered that OpenVPN incorrectly validated authentication tokens when external authentication was enabled. A remote attacker could possibly use this issue to cause OpenVPN to crash, resulting in a denial of service. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-13122) It was discovered that OpenVPN had a memory leak when handling tls-crypt-v2 client keys. A remote attacker with a valid tls-crypt-v2 client key could possibly use this issue to cause OpenVPN to consume excessive resources, leading to a denial of service. (CVE-2026-13698) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS openvpn 2.7.0-1ubuntu1.2 Ubuntu 24.04 LTS openvpn 2.6.19-0ubuntu0.24.04.3 Ubuntu 22.04 LTS openvpn 2.5.11-0ubuntu0.22.04.4 After a standard system update you need to restart OpenVPN to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8540-1 CVE-2026-11771, CVE-2026-12932, CVE-2026-12996, CVE-2026-13117, CVE-2026-13122, CVE-2026-13698 Package Information: https://launchpad.net/ubuntu/+source/openvpn/2.7.0-1ubunt... https://launchpad.net/ubuntu/+source/openvpn/2.6.19-0ubun... https://launchpad.net/ubuntu/+source/openvpn/2.5.11-0ubun...
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmpWYjcACgkQcpJm3tlz hgHBeQ/7BnQmTHwHvgYS/PGvS+/Foh5Kn93id951RWN9Xrsk4027yptgGHNKZsiH oxBsLOWFuOzo0Za2uO54Db+4q/84/Dfz0hewsz12nOohv/6bRB0CqkWYPsBAETKa iKrDanrYw6TGWt+GIg4NQn8OVvNDYc9fdXBoLQasW4jIyr5kZ3vInhIBgx6L35Yr oYGeqfUTZy+Od1/k/QjA2rSeyhKZKKY7RZu6oL1HUu8ENR/iaFXg+xfTeK5Mr6l1 f5O+uIrErzBixW5ViBBHaX9FOdDbLkbP09UCo2N6OmWNoURu0exerbxrKY7/BpN8 wCbccM/oaxuKcbcc9PlBxmtUmuPZrnrfQVq42ZyCgid3b9Di2nOI+eP2X5/wtXST IoghKHDvUJuZjuc0b8gzXlH4UAVd1M5aVY7L2lyUjr0P7gAzCouOTi+/8ZaBiN0M iphUaf22zRufKeBDibcPXFQTO8EfuM97h4QNCg0OsYvLffoqAHgzMhkYZSk4FzWk qcCznyvK3EFOyhE+r98pFw5TxwHlAj2NIDkS2Yr2+4NmffI72SRDAORdeqxpnbgd dCv/2//5TvC5qWGKcMLm5shpECGzjGmt4eoiACvmlM3PKLNm5V/b8X3VEWW8VJZM P5jqJziEIs/MhDrv9NHmc/s/Wv0kR1kZTaZmalcSJMcQyqKdy8s= =nWSe -----END PGP SIGNATURE-----
