{"id":"CVE-2025-3908","details":"The configuration initialization tool in OpenVPN 3 Linux v20 through v24 on Linux allows a local attacker to use symlinks pointing at an arbitrary directory which will change the ownership and permissions of that destination directory.","modified":"2026-04-10T05:26:10.341105Z","published":"2025-05-19T15:15:23.860Z","references":[{"type":"ADVISORY","url":"https://community.openvpn.net/Security%20Announcements/CVE-2025-3908"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2025/05/20/2"}],"affected":[{"database_specific":{"unresolved_ranges":[{"events":[{"introduced":"20"},{"last_affected":"24"}]}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-3908.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}