Advisories ยป MGASA-2026-0126

Updated openvpn packages fix security vulnerabilities

Publication date: 10 May 2026
Modification date: 10 May 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2026-35058 , CVE-2026-40215

Description

CVE-2026-35058 - fix server ASSERT() on receiving a suitably malformed
packet with a valid tls-crypt-v2 key
CVE-2026-40215 - fix race condition in TLS handshake that could lead to
leaking of packet data from a previous handshake under specific
circumstances
                

References

SRPMS

9/core