[Git][security-tracker-team/security-tracker][master] 3 commits: lts: mark CVE-2026-11771/openvpn as not affecting Bullseye
Daniel Leidert (@dleidert)
dleidert at debian.org
Sat Aug 1 04:03:17 BST 2026
Daniel Leidert pushed to branch master at Debian Security Tracker / security-tracker
Commits:
cde45350 by Daniel Leidert at 2026-08-01T05:02:45+02:00
lts: mark CVE-2026-11771/openvpn as not affecting Bullseye
The vulnerable check was introduced with
https://github.com/OpenVPN/openvpn/commit/6e010d4824b7251d817cf1770e80f186000b99ae
The original check doesn't seem to be vulnerable.
- - - - -
4a24f9bb by Daniel Leidert at 2026-08-01T05:02:47+02:00
lts: mark CVE-2026-12996/openvpn as fixed in version 2.5.1-3+deb11u4
The code didnt exist originally in Bullseye. It got introduced by the upload of
2.5.1-3+deb11u3 and then fixed quickly with the upload of 2.5.1-3+deb11u4. So,
in theory, only 2.5.1-3+deb11u3 was briefly vulnerable.
- - - - -
f329f1e2 by Daniel Leidert at 2026-08-01T05:02:47+02:00
lts/dla-needed: giving back openvpn/bullseye with comments
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -24736,6 +24736,7 @@ CVE-2026-13698 (A memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 thr
CVE-2026-11771 (OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allo ...)
{DSA-6376-1 DLA-4666-1}
- openvpn 2.7.5-1
+ [bullseye] - openvpn <not-affected> (Vulnerable code introduced later)
NOTE: Fixed by: https://github.com/OpenVPN/openvpn/commit/04309bfe0313c09edd02c29945893b9d7e2ca920 (v2.7.5)
CVE-2026-12932 (A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5 ...)
{DSA-6376-1 DLA-4666-1}
@@ -24753,7 +24754,9 @@ CVE-2026-13117 (An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alph
CVE-2026-12996 (A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 throug ...)
{DSA-6376-1 DLA-4666-1}
- openvpn 2.7.5-1
+ [bullseye] - openvpn 2.5.1-3+deb11u4
NOTE: Fixed by: https://github.com/OpenVPN/openvpn/commit/5ee1f9b90fe03ecf7cef5431147ecaabbe96db9e (v2.7.5)
+ NOTE: The issue is caused by the patch for CVE-2026-40215. Bullseye's version contains the fix for both.
CVE-2026-49838
- gobgp 4.7.0-1
[trixie] - gobgp <no-dsa> (Minor issue)
=====================================
data/dla-needed.txt
=====================================
@@ -594,9 +594,11 @@ opensc
NOTE: 20260731: Added by Front-Desk (ta)
NOTE: 20260731: lots of no-dsa issues piled up (ta)
--
-openvpn/bullseye (dleidert)
+openvpn/bullseye
NOTE: 20260703: Added by Front-Desk (dleidert)
NOTE: 20260703: A regression has been reported; and a new set of CVEs is out (dleidert/front-desk)
+ NOTE: 20260706: The regression has been fixed. (dleidert)
+ NOTE: 20260731: The new CVEs require a more thorough examination. (dleidert)
--
openvswitch/bullseye
NOTE: 20260405: Added by Front-Desk (ta)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/656744995701b2f0ae938bbcf2c8023a499182ff...f329f1e229ee18393d4d310129b56bb20270f44e
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/656744995701b2f0ae938bbcf2c8023a499182ff...f329f1e229ee18393d4d310129b56bb20270f44e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260801/a30071d1/attachment.htm>
More information about the debian-security-tracker-commits
mailing list