CVE-2025-3908 - OpenVPN 3 Linux, openvpn3-admin init-config follows symlink
The OpenVPN 3 Linux v20 introduced a new helper command to help getting an initial base configuration adopted to the currently running host. It was discovered that this tool will follow symlinks when changing ownership and permissions on two if the directories the OpenVPN 3 Linux D-Bus services depends on.
This has been resolved in OpenVPN 3 Linux v24.1.
https://www.cve.org/CVERecord?id=CVE-2025-3908
Reported by: Wolfgang Frisch, SUSE Security team
