[Bug 294712] security/openvpn-devel: please upgrade to upstream commit 64fae9d829 (20260422)
- Reply: bugzilla-noreply_a_freebsd.org: "[Bug 294712] security/openvpn-devel: please upgrade to upstream commit 64fae9d829 (20260422)"
- Reply: bugzilla-noreply_a_freebsd.org: "[Bug 294712] security/openvpn-devel: please upgrade to upstream commit 64fae9d829 (20260422)"
- Reply: bugzilla-noreply_a_freebsd.org: "[Bug 294712] security/openvpn-devel: please upgrade to upstream commit 64fae9d829 (20260422)"
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Wed, 22 Apr 2026 20:21:09 UTC
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=294712
Bug ID: 294712
Summary: security/openvpn-devel: please upgrade to upstream
commit 64fae9d829 (20260422)
Product: Ports & Packages
Version: Latest
Hardware: Any
OS: Any
Status: New
Severity: Affects Some People
Priority: ---
Component: Individual Port(s)
Assignee: ports-bugs@FreeBSD.org
Reporter: gert@greenie.muc.de
Hi,
openvpn-devel wants an update.
Besides the usual code maintenance things, and minor bug fixes, there are two
relevant security fixes that have earned a CVE number
- fix race condition in TLS handshake that could lead to leaking of
packet data from a previous handshake under specific circumstances
(CVE-2026-40215)
(Bug found by XlabAI Team of Tencent Xuanwu Lab (xlabai@tencent.com))
- fix server ASSERT() on receiving a suitably malformed packet with
a valid tls-crypt-v2 key (CVE-2026-35058)
(Bug found by XlabAI Team of Tencent Xuanwu Lab (xlabai@tencent.com)
and independently by Emma Reuter of Cisco ASIG (TALOS-2026-2381))
(upstream commit 64fae9d829 and fa129d7153).
I will attach a patch for the port itself right away.
Working my way through the vuxml documentation and examples, and should be able
to provide an update for that tomorrow.
--
You are receiving this mail because:
You are the assignee for the bug.