[CLSA-2026:1789639853] Fix CVE(s): CVE-2026-12932
Type:
security
Severity:
Important
Release date:
2026-09-17 10:11:04 UTC
Description:
* SECURITY UPDATE: Fix metadata buffer leak in tls-crypt-v2 client key extraction - debian/patches/CVE-2026-12932.patch: make the tls-crypt-v2 metadata a local variable instead of a tls_wrap_ctx member and always free it on every exit path in tls_crypt_v2_extract_client_key - CVE-2026-12932
CVEs fixed:
Updated packages:
  • openvpn_2.5.1-3+deb11u4+tuxcare.els2_amd64.deb
    sha:8953e4bd64c9c8da8963bec0785d4939469efe4b
  • openvpn_2.5.1-3+deb11u4+tuxcare.els2_arm64.deb
    sha:ef5c1395ecd94f9d0a7ff00d7f9997388a16063a
  • openvpn_2.5.1-3+deb11u4+tuxcare.els2_armel.deb
    sha:912ec30da2a74bbb2321b56eefbde68dd68c7e32
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.