# CVE-2025-3908 - OpenVPN 3 Linux, openvpn3-admin init-config follows symlink 
The OpenVPN 3 Linux v20 introduced a new command, `openvpn3-admin init-config`, to help getting an initial base configuration adopted to the currently running host.  This command must be run as `root`.

It was discovered that this tool will follow symlinks when changing ownership and permissions on two of the directories the OpenVPN 3 Linux D-Bus services depends on.

All versions from v20 through v24 are affected.  This has been resolved in OpenVPN 3 Linux v24.1.

https://www.cve.org/CVERecord?id=CVE-2025-3908

Reported by: Wolfgang Frisch, SUSE Security team
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9