Release date:
2026-08-12 00:42:45 UTC
Description:
* SECURITY UPDATE: Use-after-free of a pending dedicated ACK buffer when a
TLS session is freed during session promotion or expiry
- debian/patches/CVE-2026-12996.patch: add the check_session_buf_not_used()
safeguard, including its ks->ack_write_buf check, and call it before
every site in tls_multi_process() that frees or resets a session
- CVE-2026-12996
- the safeguard does not exist in 2.4.7, so it is introduced here already
in its post-CVE-2026-12996 form; as a result this patch also fixes
CVE-2026-40215, which shares the same safeguard
Updated packages:
-
openvpn_2.4.7-1+deb10u1+tuxcare.els2_amd64.deb
sha:c64544a8bf93472cdfd2c6af597358f4e5dc37b5
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.