Amazon Linux 2023 Security Advisory: ALAS2023-2026-2038
Advisory Released Date: 2026-08-04
Advisory Updated Date: 2026-08-04
FAQs regarding Amazon Linux ALAS/CVE Severity
OpenVPN memory-leak in tls-crypt-v2 client key handling that could lead to out-of-memory situations and subsequent server crashes (CVE-2026-12932)
When dynamic tls-crypt is active, it is possible for tls_multi_process to set to_link to session->tls_wrap_reneg.work and later free that session, leaving to_link.data pointing to freed memory. (CVE-2026-13117)
An internal server error condition that can be triggered by a malicous authenticated client, a very unlucky corruption of packets in transit or by an attacker that is able to inject a specially created packet at the right time and is able to observe the traffic to construct the packet. (CVE-2026-13698)
Affected Packages:
openvpn
Issue Correction:
Run dnf update openvpn --releasever 2023.12.20260803 or dnf update --advisory ALAS2023-2026-2038 --releasever 2023.12.20260803 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation
aarch64:
openvpn-devel-2.6.12-1.amzn2023.0.7.aarch64
openvpn-debugsource-2.6.12-1.amzn2023.0.7.aarch64
openvpn-debuginfo-2.6.12-1.amzn2023.0.7.aarch64
openvpn-2.6.12-1.amzn2023.0.7.aarch64
src:
openvpn-2.6.12-1.amzn2023.0.7.src
x86_64:
openvpn-debuginfo-2.6.12-1.amzn2023.0.7.x86_64
openvpn-devel-2.6.12-1.amzn2023.0.7.x86_64
openvpn-debugsource-2.6.12-1.amzn2023.0.7.x86_64
openvpn-2.6.12-1.amzn2023.0.7.x86_64