========================================================================== Ubuntu Security Notice USN-7898-1 November 27, 2025
openvpn vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 25.04 - Ubuntu 24.04 LTS Summary: OpenVPN could allow unintended access to network services. Software Description: - openvpn: virtual private network software Details: Joshua Rogers discovered that OpenVPN incorrectly handled HMAC verification checks. A remote attacker could possibly use this issue to bypass source IP address validation. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 openvpn 2.6.14-2ubuntu1.1 Ubuntu 25.04 openvpn 2.6.14-0ubuntu0.25.04.3 Ubuntu 24.04 LTS openvpn 2.6.14-0ubuntu0.24.04.3 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7898-1 CVE-2025-13086 Package Information: https://launchpad.net/ubuntu/+source/openvpn/2.6.14-2ubuntu1.1 https://launchpad.net/ubuntu/+source/openvpn/2.6.14-0ubuntu0.25.04.3 https://launchpad.net/ubuntu/+source/openvpn/2.6.14-0ubuntu0.24.04.3
signature.asc
Description: OpenPGP digital signature
