USN-8852-1: OpenVPN vulnerabilities
Checked 1 Oct 2026. BlackTree preserves the last verified facts if a later source check is temporarily unavailable.
Open the official publisher sourcePUBLISHER UPDATE · USN-8852-1
USN-8852-1: OpenVPN vulnerabilities
Scope: Ubuntu. This update record adds version, fix and known-issue context. Its publication date is not a lifecycle boundary.
It was discovered that OpenVPN had a use-after-free vulnerability in its TLS session handling. An attacker could possibly use this issue to cause OpenVPN to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-84471) It was discovered that OpenVPN incorrectly handled retransmissions of ACK packet IDs, which could trigger a timeout integer overflow. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2026-84732)
Not stated. The verified publisher record does not contain a known-issues statement.
Review the official publisher document before deployment.
These links connect the publisher update to related Lifecycle records without treating the update publication date as an end-of-support date.
Checked 1 Oct 2026. BlackTree preserves the last verified facts if a later source check is temporarily unavailable.
Open the official publisher source