Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <65ddb8ca-0ea5-43bc-8f7a-15ed4281ccc3@eurephia.org>
Date: Tue, 20 May 2025 11:48:24 +0200
From: David Sommerseth <dazo@...ephia.org>
To: oss-security@...ts.openwall.com
Cc: SUSE Security <security@...e.de>, Wolfgang Frisch <wfrisch@...e.de>,
 "security@...nvpn.net" <security@...nvpn.net>
Subject: CVE-2025-3908: OpenVPN 3 Linux v24.1 released


OpenVPN 3 Linux v24.1 was released 2025-05-19 which includes a fix for
CVE-2025-3908.

The OpenVPN 3 Linux v20 introduced a new command, openvpn3-admin
init-config, to help getting an initial base configuration adopted to
the currently running host. This command must be run as root.

It was discovered that this tool will follow symlinks when changing
ownership and permissions on two of the directories the OpenVPN 3 Linux
D-Bus services depends on.

All versions from v20 through v24 are affected. This has been resolved
in OpenVPN 3 Linux v24.1.

<https://community.openvpn.net/Security%20Announcements/CVE-2025-3908>
<https://www.cve.org/CVERecord?id=CVE-2025-3908>

We want to thank Wolfgang Frisch from the SUSE Security team for
reporting this issue.


-- 
kind regards,

David Sommerseth
OpenVPN Inc


Download attachment "OpenPGP_signature.asc" of type "application/pgp-signature" (834 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.