OpenVPN Vulnerabilities Lead to Denial of Service Risks

OpenVPN Vulnerabilities Lead to Denial of Service Risks

First seen 21 May 2026, 03:26 UTC UbuntuLinuxsecuritylaunchpad.net 90% similarity 57.8

Article Content

Browse articles
ThreatCluster

OpenVPN has been found to have multiple vulnerabilities that could lead to denial of service and sensitive data leakage. Discovered by researchers Guannan Wang, Zhanpeng Liu, Guancheng Li, and Emma Reuter, these issues affect several Ubuntu releases, including 26.04 LTS and earlier versions. The first vulnerability (CVE-2026-35058) allows attackers to crash OpenVPN by sending malformed packets. The second vulnerability (CVE-2026-40215) involves a race condition in the TLS handshake process, which could leak sensitive packet data. Users are advised to update their systems to mitigate these risks. The vulnerabilities were disclosed on May 20, 2026, and patches are available through standard system updates.

Key Points: • OpenVPN vulnerabilities could lead to denial of service and data leakage. • Affected Ubuntu versions include 26.04 LTS, 25.10, and 24.04 LTS. • Users should update their systems to the latest package versions to mitigate risks.

ThreatCluster AI

Timeline

2026-05-20
OpenVPN vulnerabilities disclosed
Researchers reported vulnerabilities in OpenVPN, including denial of service and data leakage risks. Users are urged to update their systems.
Ubuntu
2026-05-20
Ubuntu security notice USN-8286-1 issued
Ubuntu released a security notice detailing vulnerabilities in OpenVPN affecting multiple LTS versions.
Linuxsecurity

Community

Browse all →

Tracked Entities in This Story