[Bug 294712] security/openvpn-devel: please upgrade to upstream commit 64fae9d829 (20260422)

From: <bugzilla-noreply_at_freebsd.org>
Date: Wed, 22 Apr 2026 20:21:09 UTC
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=294712

            Bug ID: 294712
           Summary: security/openvpn-devel: please upgrade to upstream
                    commit 64fae9d829 (20260422)
           Product: Ports & Packages
           Version: Latest
          Hardware: Any
                OS: Any
            Status: New
          Severity: Affects Some People
          Priority: ---
         Component: Individual Port(s)
          Assignee: ports-bugs@FreeBSD.org
          Reporter: gert@greenie.muc.de

Hi,

openvpn-devel wants an update.

Besides the usual code maintenance things, and minor bug fixes, there are two
relevant security fixes that have earned a CVE number

      - fix race condition in TLS handshake that could lead to leaking of
        packet data from a previous handshake under specific circumstances
        (CVE-2026-40215)

        (Bug found by XlabAI Team of Tencent Xuanwu Lab (xlabai@tencent.com))

      - fix server ASSERT() on receiving a suitably malformed packet with
        a valid tls-crypt-v2 key (CVE-2026-35058)

        (Bug found by XlabAI Team of Tencent Xuanwu Lab (xlabai@tencent.com)
         and independently by Emma Reuter of Cisco ASIG (TALOS-2026-2381))

(upstream commit 64fae9d829 and fa129d7153).

I will attach a patch for the port itself right away.

Working my way through the vuxml documentation and examples, and should be able
to provide an update for that tomorrow.

-- 
You are receiving this mail because:
You are the assignee for the bug.