-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 01 Jul 2026 22:20:55 +0200 Source: openvpn Binary: openvpn openvpn-dbgsym Architecture: s390x Version: 2.6.14-1+deb13u3 Distribution: trixie-security Urgency: high Maintainer: s390x Build Daemon (zandonai) Changed-By: Bernhard Schmidt Description: openvpn - virtual private network daemon Changes: openvpn (2.6.14-1+deb13u3) trixie-security; urgency=high . * Cherry-pick upstream security patches from the 2.6.21 release - CVE-2026-12996: Fix use-after-free bug in ack_write_buf(), triggerable by a well-timed sequence of control channel + authentication packets - CVE-2026-13117: Fix use-after-free bug in tls_wrap_reneg(), triggerable by suitable sequence of dynamic tls-crypt control-channel packets - CVE-2026-13122: Fix server crash on reception of suitably malformed auth-token, if --auth-gen-token external-auth is active - CVE-2026-12932: Fix memory-leak in tls-crypt-v2 client key handling that could lead to out-of-memory situations and subsequent server crashes - CVE-2026-11771: Fix possible 1-byte buffer overrun on NTLMv2 proxy responses. - CVE-2026-13698: Fix another memory leak on reception of suitable tls-crypt-v2 packets that could lead to an out of memory situation and server crash Checksums-Sha1: 3d35e0742b3fc62e5fc30217525d958fed2fe24a 1266060 openvpn-dbgsym_2.6.14-1+deb13u3_s390x.deb 5477c1a07c7f9842157fc6ac5d51a6f6faf2e884 7147 openvpn_2.6.14-1+deb13u3_s390x-buildd.buildinfo 0c6e282c83120e97a51b0e7132d4d84ac2a56a3d 631920 openvpn_2.6.14-1+deb13u3_s390x.deb Checksums-Sha256: caf0a12254aa0f9ae2b344001b31146af7350a2fc24b9b1be10a8dbe80c80217 1266060 openvpn-dbgsym_2.6.14-1+deb13u3_s390x.deb 0dabcb6f2f54941eafdb544f0cfc432f448356b0cb8b393feb70ccdc9dcc3472 7147 openvpn_2.6.14-1+deb13u3_s390x-buildd.buildinfo 7a7720cb73919f0b56579bb3e34fa79d4f131400fc4b6fd4a3d88e599577e79c 631920 openvpn_2.6.14-1+deb13u3_s390x.deb Files: 7c25ea1488b7cc1971a47c5ea3aa1c61 1266060 debug optional openvpn-dbgsym_2.6.14-1+deb13u3_s390x.deb 598820a92e3158ec823ba41c172cddba 7147 net optional openvpn_2.6.14-1+deb13u3_s390x-buildd.buildinfo 222fa12f836497fa486e1748f64b33f5 631920 net optional openvpn_2.6.14-1+deb13u3_s390x.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEENly2ANlpa4eeqnluvVOPI7pYNpgFAmpG5psACgkQvVOPI7pY NphddQ//b5PI9r/ZyyH23fZ/v3Vm7OXA2Oo57coHnDhDEsTCoq6xocfmBHynRYev ZjNJUtdpkjICTWcM4To54aM7KFuCRfaFUvaWLdNx4Xb60iHtJFyD0UJH4XjyI93Z OLPEgQd5ScdrxfbJL/h2khmX1GoIbrRUZ6eVjtI0fGAPjG6LAq4aQp33aSmX5nzI LUtMfDm9SYiheY7ISCnxCyEdkZRPS7X7E6U+fQLaEZzGA1Gk8jHJqo/Ui4+EQWoj OoOgHPDcmcMy+sVdDwudiX1i/Wcux9Y9TF89wFa0p4HC6zzaoPH6Jqz6MFYo9D5S NuUQivNcjlJ0t/sn9RhAAxC0NuFuq+ppntwOZS8Zoe9WEVWs6loiyYww2YmoUziu 4TrqOd4omtHaN/Ah1x+gsBeTXpS/AY3kMrQf65bb4fW+9I0EljbtAxAMXhSuq0DL /Zqoz0874AX2Hd1Zy4/c8JDYRXhzsbSA5/naaVErWXePO+OqyMDMGx4Xcwu3ulCc 3kWPVTYKrqvirfP+3VrbBHa84XyXmdMHifqGxoZu/z027qiZCud8plT45DRF7TFc FTpooSKH6lY76lgz2MrBWqVAc4Dz9Emq53ssDAyQrKFl0SGu9RBEYazYoyF33aWF qgEwmKQOyOeivEmJR8TalumYRRHtaRUtgfPjwncYwuFGioVXl24= =VzIn -----END PGP SIGNATURE-----