#1141326 openvpn: Segfault after 2.5.1-3+deb11u3 upgrade 

Package:
openvpn
Source:
openvpn
Description:
virtual private network daemon
Submitter:
Youri Bonnaffe
Date:
2026-07-05 20:53:01 UTC
Severity:
normal
#1141326#5
Date:
2026-07-02 22:20:30 UTC
From:
To:
Dear Maintainer,

Upgrading openvpn from 2.5.1-3 to 2.5.1-3+deb11u3 lead to segfault crashes.
I'm seeing TLS timeouts too in the logs but I'm unsure if those are correlated.

[Thu Jul  2 23:12:05 2026] openvpn[2387385]: segfault at 0 ip 000055f1ee7aec87 sp 00007ffc69242b50 error 4 in openvpn[55f1ee73d000+86000]
[Thu Jul  2 23:12:05 2026] Code: f2 8b 05 3c 55 05 00 45 31 ed 85 c0 75 53 c7 43 08 00 00 00 00 48 c7 43 10 00 00 00 00 5b 41 5c 41 5d c3 48 8b 8e 18 05 00 00 <8b> 11 85 d2 7e ed 48 8b 49 70 45 31 e4 eb 13 66 2e 0f 1f 84 00 00

Symbols are stripped in the binary so I could not get more information.

Rolling back the openvpn version fixed the issue.

I understand this version of Debian is not supported anymore, and this will likely get no fix.
But I thought about reporting it to document it for others.

Regards,

Youri

#1141326#10
Date:
2026-07-03 12:16:24 UTC
From:
To:
Hi Youri,
 >

It is suppported by the Debian LTS team. The last upload of
2.5.1-3+deb11u3 was done by Daniel Leidert, copying him.

One immediate question, you said downgrading to -3 fixed it. However,
there were several versions in between, a -3+deb11u1 in March 2025 and a
-3+deb11u2 in August 2025. It would be good to know if this problem was 
introduced in +deb11u3 just now.

Could you test downgrading to deb11u2?

Bernhard

#1141326#15
Date:
2026-07-03 15:11:25 UTC
From:
To:
Hi,

@LTS-coordinator: Please be aware.

Am Freitag, dem 03.07.2026 um 14:16 +0200 schrieb Bernhard Schmidt:
LTS team from other sources.

I've already looked into it and spotted the possible cause. The issue
has likely been caused by one of the patches to address CVE-2026-40215
which introduces check_session_buf_not_used(). I'm in the process of
checking that further. @Bernhard: Trixie is not affected. It contains
the necessary changes in this function.

On a sidenote: The fix introduces CVE-2026-12996 and CVE-2026-13117,
which were just published and addressed by upstream a few days ago (and
here, Trixie is affected).

Yes, it would very much help to narrow it down and confirm it. Also,
please provide all information that you have.

Regards, Daniel

#1141326#20
Date:
2026-07-03 15:41:56 UTC
From:
To:
That version can be found at
https://snapshot.debian.org/package/openvpn/2.5.1-3%2Bdeb11u2/

Cheers,
Emilio

#1141326#25
Date:
2026-07-05 20:40:21 UTC
From:
To:
Hi,

Unfortunately, this issue was not visible in test environments, and I don't have a reproducer for now, so testing will be a bit difficult in my situation.
I still tried a short test for 30m, using deb11u2. I didn't observe crashes, but this was just for a short period of time.

Regards,

Youri

Enphase Confidential


That version can be found at
https://urldefense.com/v3/__https://snapshot.debian.org/package/openvpn/2.5.1-3*2Bdeb11u2/__;JQ!!J0D89H32QIeNiQ!yJJ5T12YZX1BoDLFoN8NC09DlaTFNm31pUcEVTdrccp4oCAYwfffdnDLqKFgJiEH6G96ZXDM_JMkrRYKBqER$

Cheers,
Emilio