USN-8852-1: OpenVPN vulnerabilities
Ubuntu warns OpenVPN flaws could allow remote code execution or denial of service.
Ubuntu published USN-8852-1 for two OpenVPN vulnerabilities. CVE-2026-84471 is a use-after-free in TLS session handling that could crash OpenVPN or allow arbitrary code execution. CVE-2026-84732 is an integer overflow triggered by retransmitted ACK packet IDs that a remote attacker could use for denial of service. The notice does not say either flaw is being exploited.
64