Описание
Security update for openvpn
This update for openvpn fixes the following issues:
- CVE-2026-13122: denial of service via a malformed authentication token that triggers a reachable assertion when external-auth is enabled (bsc#1270413).
- CVE-2026-13698: denial of service via memory leak triggered by remote attackers with a valid tls-crypt-v2 client key (bsc#1270414).
Список пакетов
openSUSE Leap 16.0
openvpn-2.6.10-160000.4.1
openvpn-auth-pam-plugin-2.6.10-160000.4.1
openvpn-devel-2.6.10-160000.4.1
openvpn-down-root-plugin-2.6.10-160000.4.1
Ссылки
- SUSE Security Ratings
- SUSE Bug 1270413
- SUSE Bug 1270414
- SUSE CVE CVE-2026-13122 page
- SUSE CVE CVE-2026-13698 page
Описание
OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service via a malformed authentication token that triggers a reachable assertion when external-auth is enabled
Затронутые продукты
openSUSE Leap 16.0:openvpn-2.6.10-160000.4.1
openSUSE Leap 16.0:openvpn-auth-pam-plugin-2.6.10-160000.4.1
openSUSE Leap 16.0:openvpn-devel-2.6.10-160000.4.1
openSUSE Leap 16.0:openvpn-down-root-plugin-2.6.10-160000.4.1
Ссылки
- CVE-2026-13122
- SUSE Bug 1270413
Описание
A memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers with a valid tls-crypt-v2 client key to potentially cause a denial of service
Затронутые продукты
openSUSE Leap 16.0:openvpn-2.6.10-160000.4.1
openSUSE Leap 16.0:openvpn-auth-pam-plugin-2.6.10-160000.4.1
openSUSE Leap 16.0:openvpn-devel-2.6.10-160000.4.1
openSUSE Leap 16.0:openvpn-down-root-plugin-2.6.10-160000.4.1
Ссылки
- CVE-2026-13698
- SUSE Bug 1270414