[Git][security-tracker-team/security-tracker][master] 3 commits: lts: mark CVE-2026-11771/openvpn as not affecting Bullseye

Daniel Leidert (@dleidert) dleidert at debian.org
Sat Aug 1 04:03:17 BST 2026



Daniel Leidert pushed to branch master at Debian Security Tracker / security-tracker


Commits:
cde45350 by Daniel Leidert at 2026-08-01T05:02:45+02:00
lts: mark CVE-2026-11771/openvpn as not affecting Bullseye

The vulnerable check was introduced with
https://github.com/OpenVPN/openvpn/commit/6e010d4824b7251d817cf1770e80f186000b99ae

The original check doesn't seem to be vulnerable.

- - - - -
4a24f9bb by Daniel Leidert at 2026-08-01T05:02:47+02:00
lts: mark CVE-2026-12996/openvpn as fixed in version 2.5.1-3+deb11u4

The code didnt exist originally in Bullseye. It got introduced by the upload of
2.5.1-3+deb11u3 and then fixed quickly with the upload of 2.5.1-3+deb11u4. So,
in theory, only 2.5.1-3+deb11u3 was briefly vulnerable.

- - - - -
f329f1e2 by Daniel Leidert at 2026-08-01T05:02:47+02:00
lts/dla-needed: giving back openvpn/bullseye with comments

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -24736,6 +24736,7 @@ CVE-2026-13698 (A memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 thr
 CVE-2026-11771 (OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allo ...)
 	{DSA-6376-1 DLA-4666-1}
 	- openvpn 2.7.5-1
+	[bullseye] - openvpn <not-affected> (Vulnerable code introduced later)
 	NOTE: Fixed by: https://github.com/OpenVPN/openvpn/commit/04309bfe0313c09edd02c29945893b9d7e2ca920 (v2.7.5)
 CVE-2026-12932 (A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5 ...)
 	{DSA-6376-1 DLA-4666-1}
@@ -24753,7 +24754,9 @@ CVE-2026-13117 (An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alph
 CVE-2026-12996 (A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 throug ...)
 	{DSA-6376-1 DLA-4666-1}
 	- openvpn 2.7.5-1
+	[bullseye] - openvpn 2.5.1-3+deb11u4
 	NOTE: Fixed by: https://github.com/OpenVPN/openvpn/commit/5ee1f9b90fe03ecf7cef5431147ecaabbe96db9e (v2.7.5)
+	NOTE: The issue is caused by the patch for CVE-2026-40215. Bullseye's version contains the fix for both.
 CVE-2026-49838
 	- gobgp 4.7.0-1
 	[trixie] - gobgp <no-dsa> (Minor issue)


=====================================
data/dla-needed.txt
=====================================
@@ -594,9 +594,11 @@ opensc
   NOTE: 20260731: Added by Front-Desk (ta)
   NOTE: 20260731: lots of no-dsa issues piled up (ta)
 --
-openvpn/bullseye (dleidert)
+openvpn/bullseye
   NOTE: 20260703: Added by Front-Desk (dleidert)
   NOTE: 20260703: A regression has been reported; and a new set of CVEs is out (dleidert/front-desk)
+  NOTE: 20260706: The regression has been fixed. (dleidert)
+  NOTE: 20260731: The new CVEs require a more thorough examination. (dleidert)
 --
 openvswitch/bullseye
   NOTE: 20260405: Added by Front-Desk (ta)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/656744995701b2f0ae938bbcf2c8023a499182ff...f329f1e229ee18393d4d310129b56bb20270f44e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/656744995701b2f0ae938bbcf2c8023a499182ff...f329f1e229ee18393d4d310129b56bb20270f44e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260801/a30071d1/attachment.htm>


More information about the debian-security-tracker-commits mailing list