-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Tue, 18 Nov 2025 22:49:31 +0100
Source: openvpn
Architecture: source
Version: 2.7.0~rc2-1
Distribution: experimental
Urgency: medium
Maintainer: Bernhard Schmidt <berni@debian.org>
Changed-By: Bernhard Schmidt <berni@debian.org>
Changes:
openvpn (2.7.0~rc2-1) experimental; urgency=medium
.
* New upstream version 2.7.0~rc2
- CVE-2025-12106
IPv6 address parsing: fix buffer overread on invalid input
- CVE-2025-13086
HMAC verification check: fix incorrect memcmp() call
Checksums-Sha1:
d98edfb3708afadd42152708c284b5ffbdc7fcb0 2274 openvpn_2.7.0~rc2-1.dsc
64dbcb75012e3a8c2e2e6a6aee4367ef8ba41eac 2080851 openvpn_2.7.0~rc2.orig.tar.gz
1e87bc2269604bdb7f6d84a219456fd404c15877 60008 openvpn_2.7.0~rc2-1.debian.tar.xz
036b3f1c1b4e03d19efe006e2c1f2329714e58bd 7162 openvpn_2.7.0~rc2-1_amd64.buildinfo
Checksums-Sha256:
c358ca486be1c4147f2ca0aa0546222acb1d6574cefb2ccafdb690603ab7b75b 2274 openvpn_2.7.0~rc2-1.dsc
6623e8b397dda3a7c05f041099f2f5acb038ea833afded94e7f2811da8b09eae 2080851 openvpn_2.7.0~rc2.orig.tar.gz
068b8ab4cc4ed16e261298b5e6afccfbed430f3cdf2404977cd6952fc461aae2 60008 openvpn_2.7.0~rc2-1.debian.tar.xz
45cc6bce2ae0c90ec19bd7979a7bc0bfb5c3de950dec444a8ca4e1cf71b5627d 7162 openvpn_2.7.0~rc2-1_amd64.buildinfo
Files:
fdba08587358285382e5aae14ba82a18 2274 net optional openvpn_2.7.0~rc2-1.dsc
e1c60917bcf5e5adca735373a1d6b14e 2080851 net optional openvpn_2.7.0~rc2.orig.tar.gz
c598edfdba389960e0b2eb32ca6820d0 60008 net optional openvpn_2.7.0~rc2-1.debian.tar.xz
b36a6c98592d797a83b90d272099fdb8 7162 net optional openvpn_2.7.0~rc2-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJFBAEBCgAvFiEE1uAexRal3873GVbTd1B55bhQvJMFAmkc7mARHGJlcm5pQGRl
Ymlhbi5vcmcACgkQd1B55bhQvJNBWQ//UYtaYTQ+gCJI04M3rKm9fQe1bOcwm293
XHD9IV17YqYRw9zKxIa1jweZyefmyDj8FGBXx8aOv6HT5LOJbmMMmKievu3Mcso0
Xqaklocs3245GDFf50MwL4AhkMUkR5tPCrbozt/qL6UQq/96l/uD5LJi0wFqTkGN
CxIMwi87aTu5N7jE7a6zJv7kVFKIXOh5LD67ByryZ35bIB1PJpVFVpPy3vr5+UBS
NbDxVB4HVwmdKoPopRP1Kp1F8vghWPMpqQ7DnQLz2xw+UhHhgPOjsrAjBC2BSCVR
9M3Rk+/2N3K4bvp/Lyfr8+k6qFK8p5tDpZ3apUyKSuIX1oq2TGAjpOMnEQeFB/H0
Hx4FQqMdGewr4Soh/WDODwB4g5lbMLF5O+twSJAJ+quO7B0/evLQyENcK7/oa/i6
rTyfNmjUajSoASOQWy8829HzqzmVtOSJT8NGgSnP0LiZsGUtjC3uE7DtTy+9vTe/
KIWxaUTh+Q4FVjdfQfgYwYY/vV0s+P6iW0WdmFW3xSOJfJKFR8IaWJVEe54fPlYa
O0WBIyZzs2uWHkKdCvBT8OEVGnX6LsXGF072AHhQ+rXqDBGFNhESqIbA3ZJ7qQvm
ECVoPeiluDJ/bVgFrFOoBP4skRifF8IpO0B26rcA0Zo7FAWmdmPQ+smbZS2GLnnq
D84+B/f/US8=
=OhHr
-----END PGP SIGNATURE-----