Linuxsecurity OpenVPN Vulnerabilities Lead to Denial of Service Risks
Article Content
- •OpenVPN vulnerabilities could lead to denial of service and data leakage.
- •Affected Ubuntu versions include 26.04 LTS, 25.10, and 24.04 LTS.
- •Users should update their systems to the latest package versions to mitigate risks.
OpenVPN has been found to have multiple vulnerabilities that could lead to denial of service and sensitive data leakage. Discovered by researchers Guannan Wang, Zhanpeng Liu, Guancheng Li, and Emma Reuter, these issues affect several Ubuntu releases, including 26.04 LTS and earlier versions. The first vulnerability (CVE-2026-35058) allows attackers to crash OpenVPN by sending malformed packets. The second vulnerability (CVE-2026-40215) involves a race condition in the TLS handshake process, which could leak sensitive packet data. Users are advised to update their systems to mitigate these risks. The vulnerabilities were disclosed on May 20, 2026, and patches are available through standard system updates.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Ubuntu and CVE-2026-35058 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
openSUSE Vulnerabilities: Memory Leak and DoS Threats Identified Recent updates for openSUSE address critical vulnerabilities in OpenVPN and c-ares. The OpenVPN vulnerabilities (CVE-2026-12932 and CVE-2026-35058) involve a moderate memory leak and improper validation of packet lengths, potentially leading to denial of service. These vulnerabilities affect openSUSE Leap 15.4…
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…