CVE-2025-3908

Publication date 19 May 2025

Last updated 21 May 2025


Ubuntu priority

The configuration initialization tool in OpenVPN 3 Linux v20 through v24 on Linux allows a local attacker to use symlinks pointing at an arbitrary directory which will change the ownership and permissions of that destination directory.

Status

Package Ubuntu Release Status
openvpn3-client 25.04 plucky
Needs evaluation
24.10 oracular Not in release
24.04 LTS noble Not in release
22.04 LTS jammy Not in release
20.04 LTS focal Not in release