Release date:
2026-09-17 10:11:04 UTC
Description:
* SECURITY UPDATE: Fix metadata buffer leak in tls-crypt-v2 client key extraction
- debian/patches/CVE-2026-12932.patch: make the tls-crypt-v2 metadata a
local variable instead of a tls_wrap_ctx member and always free it on
every exit path in tls_crypt_v2_extract_client_key
- CVE-2026-12932
Updated packages:
-
openvpn_2.5.1-3+deb11u4+tuxcare.els2_amd64.deb
sha:8953e4bd64c9c8da8963bec0785d4939469efe4b
-
openvpn_2.5.1-3+deb11u4+tuxcare.els2_arm64.deb
sha:ef5c1395ecd94f9d0a7ff00d7f9997388a16063a
-
openvpn_2.5.1-3+deb11u4+tuxcare.els2_armel.deb
sha:912ec30da2a74bbb2321b56eefbde68dd68c7e32
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.