-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 01 Jul 2026 22:20:55 +0200 Source: openvpn Binary: openvpn openvpn-dbgsym Architecture: ppc64el Version: 2.6.14-1+deb13u3 Distribution: trixie-security Urgency: high Maintainer: ppc64el Build Daemon (ppc64el-conova-02) Changed-By: Bernhard Schmidt Description: openvpn - virtual private network daemon Changes: openvpn (2.6.14-1+deb13u3) trixie-security; urgency=high . * Cherry-pick upstream security patches from the 2.6.21 release - CVE-2026-12996: Fix use-after-free bug in ack_write_buf(), triggerable by a well-timed sequence of control channel + authentication packets - CVE-2026-13117: Fix use-after-free bug in tls_wrap_reneg(), triggerable by suitable sequence of dynamic tls-crypt control-channel packets - CVE-2026-13122: Fix server crash on reception of suitably malformed auth-token, if --auth-gen-token external-auth is active - CVE-2026-12932: Fix memory-leak in tls-crypt-v2 client key handling that could lead to out-of-memory situations and subsequent server crashes - CVE-2026-11771: Fix possible 1-byte buffer overrun on NTLMv2 proxy responses. - CVE-2026-13698: Fix another memory leak on reception of suitable tls-crypt-v2 packets that could lead to an out of memory situation and server crash Checksums-Sha1: 67bf8fe088368aaa86f5140e459d81bf47c1ad9a 1325556 openvpn-dbgsym_2.6.14-1+deb13u3_ppc64el.deb 38b58c91549751c7bfbfe4b1b49232c55cb2e0e1 7284 openvpn_2.6.14-1+deb13u3_ppc64el-buildd.buildinfo e26e7fe1a21d736cddd8bef3f9edd543eaf15e0a 688372 openvpn_2.6.14-1+deb13u3_ppc64el.deb Checksums-Sha256: db9c5444f22e2e67ee60421ed21c7333b0bd4ee9b8146867dee726b5300a02a4 1325556 openvpn-dbgsym_2.6.14-1+deb13u3_ppc64el.deb 6932cc15c68880fbf5c0d5cf739c299655b9221fb8bf0579fc70fa05f7306ef9 7284 openvpn_2.6.14-1+deb13u3_ppc64el-buildd.buildinfo 2089bb6f55f42a7644e9294d8d47942508b1c3f77dcaaaf9e43f7296fbbb756f 688372 openvpn_2.6.14-1+deb13u3_ppc64el.deb Files: 5c76d506adf4443283fe2b4633cc9b5f 1325556 debug optional openvpn-dbgsym_2.6.14-1+deb13u3_ppc64el.deb f2ddfb312b405076a50777d05bbd00be 7284 net optional openvpn_2.6.14-1+deb13u3_ppc64el-buildd.buildinfo df5a07c5c29f905f1bc8ee1f3ede1da0 688372 net optional openvpn_2.6.14-1+deb13u3_ppc64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEySUEQfg5pZeb/U372FRWNm40e2YFAmpG5tQACgkQ2FRWNm40 e2aWHxAAi9LFHMkG3qwqfk6EteFHVHvwIozmLm/3v+JeTV06lkWkZ3Elu+34PGP9 PVRRqdm67VwgafKM4EthDbqfbWslNDvxRiMarZ/Mr9eoyR5tBFkLhBONkAZBwWRA Eg+r6N+WNo4WFvIx1gF+WgX9TxKB6mDjAVBCHhqm4c6b/YmFnaaQXZBNia/uNzK0 YLZM0Si6iKcvNIPgazwolQtQEwTWCsctUOd6vErojemFqufJ2+f1xfm7nlx+GQ/2 em2WwXguEs7e16ZIxCRGtDd9PzPkVe4O0jN4gLncQu+xSiKjvhcB7I62dHsim25J vOgiruXlnS9jvUpqXij6MuBGU7NO7qN/NQbtUuV19nMzJ/OxSYGRGpi/8Rumjoey Oqi1t8yAhpeXF/k/xD8sAN+31P0cs5ysyMn64nsz4uXxwYy/pF9k8p//CL+ZUeBW Vb68PwOR30enFbl24LZmVL8QTlU3FvZdkgsajHk7tYBwFWxiewkGLkaegD7xkTxF s0ULbZsJcNlGxBTcjgafk8fyHTcVUnN/z+Xi55YfPr0iyqnLVHZR+bus+jhFrXno Te+kGQ6tLIEVpnfH4n0FyEWTdWzhTaUobleTUwFPq2G4Rx8lm1e45h3IAPDq4UaO RIsadDjO2Gd6LaZrF369IS4Lv7omglmtBTO1I4M25ty6ueIkWsA= =d/NH -----END PGP SIGNATURE-----