[CLSA-2026:1786495354] Fix CVE(s): CVE-2026-12996
Type:
security
Severity:
Important
Release date:
2026-08-12 00:42:45 UTC
Description:
* SECURITY UPDATE: Use-after-free of a pending dedicated ACK buffer when a TLS session is freed during session promotion or expiry - debian/patches/CVE-2026-12996.patch: add the check_session_buf_not_used() safeguard, including its ks->ack_write_buf check, and call it before every site in tls_multi_process() that frees or resets a session - CVE-2026-12996 - the safeguard does not exist in 2.4.7, so it is introduced here already in its post-CVE-2026-12996 form; as a result this patch also fixes CVE-2026-40215, which shares the same safeguard
CVEs fixed:
Updated packages:
  • openvpn_2.4.7-1+deb10u1+tuxcare.els2_amd64.deb
    sha:c64544a8bf93472cdfd2c6af597358f4e5dc37b5
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.