ELA-1762-1 openvpn security update

denial of service and heap memory leak

2026-06-27
Packageopenvpn
Version2.4.0-6+deb9u6 (stretch), 2.4.7-1+deb10u3 (buster)
Related CVEs CVE-2026-40215


A vulnerability has been discovered in OpenVPN, a virtual private network application.

CVE-2026-40215

A race condition allows remote attackers to potentially cause a server crash or leak heap memory via a use-after-free triggered during TLS session promotion.



For Debian 10 buster, these problems have been fixed in version 2.4.7-1+deb10u3.

For Debian 9 stretch, these problems have been fixed in version 2.4.0-6+deb9u6.

We recommend that you upgrade your openvpn packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.