Blame

d7f686 David Sommerseth 2025-05-19 14:58:36 1
# CVE-2025-3908 - OpenVPN 3 Linux, openvpn3-admin init-config follows symlink 
b89af0 David Sommerseth 2025-05-20 09:47:28 2
The OpenVPN 3 Linux v20 introduced a new command, `openvpn3-admin init-config`, to help getting an initial base configuration adopted to the currently running host. This command must be run as `root`.
cf36d0 David Sommerseth 2025-05-16 20:10:35 3
b89af0 David Sommerseth 2025-05-20 09:47:28 4
It was discovered that this tool will follow symlinks when changing ownership and permissions on two of the directories the OpenVPN 3 Linux D-Bus services depends on.
5
6
All versions from v20 through v24 are affected. This has been resolved in OpenVPN 3 Linux v24.1.
d7f686 David Sommerseth 2025-05-19 14:58:36 7
8
https://www.cve.org/CVERecord?id=CVE-2025-3908
9
10
Reported by: Wolfgang Frisch, SUSE Security team