{"id":"MGASA-2026-0126","summary":"Updated openvpn packages fix security vulnerabilities","details":"CVE-2026-35058 - fix server ASSERT() on receiving a suitably malformed\npacket with a valid tls-crypt-v2 key\nCVE-2026-40215 - fix race condition in TLS handshake that could lead to\nleaking of packet data from a previous handshake under specific\ncircumstances\n","modified":"2026-05-10T02:45:06.953244Z","published":"2026-05-10T02:43:56Z","upstream":["CVE-2026-35058","CVE-2026-40215"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2026-0126.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=35442"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SFR4RR6F447AZK2ZTKVGZP3NKKWFW6DW/"},{"type":"ADVISORY","url":"https://community.openvpn.net/Security%20Announcements/CVE-2026-35058"},{"type":"ADVISORY","url":"https://community.openvpn.net/Security%20Announcements/CVE-2026-40215"}],"affected":[{"package":{"name":"openvpn","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/openvpn?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.6.20-1.1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0126.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}