ALAS2023-2026-2038


Amazon Linux 2023 Security Advisory: ALAS2023-2026-2038
Advisory Released Date: 2026-08-04
Advisory Updated Date: 2026-08-04
Severity: Medium

Issue Overview:

OpenVPN memory-leak in tls-crypt-v2 client key handling that could lead to out-of-memory situations and subsequent server crashes (CVE-2026-12932)

When dynamic tls-crypt is active, it is possible for tls_multi_process to set to_link to session->tls_wrap_reneg.work and later free that session, leaving to_link.data pointing to freed memory. (CVE-2026-13117)

An internal server error condition that can be triggered by a malicous authenticated client, a very unlucky corruption of packets in transit or by an attacker that is able to inject a specially created packet at the right time and is able to observe the traffic to construct the packet. (CVE-2026-13698)


Affected Packages:

openvpn


Issue Correction:
Run dnf update openvpn --releasever 2023.12.20260803 or dnf update --advisory ALAS2023-2026-2038 --releasever 2023.12.20260803 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation

New Packages:
aarch64:
    openvpn-devel-2.6.12-1.amzn2023.0.7.aarch64
    openvpn-debugsource-2.6.12-1.amzn2023.0.7.aarch64
    openvpn-debuginfo-2.6.12-1.amzn2023.0.7.aarch64
    openvpn-2.6.12-1.amzn2023.0.7.aarch64

src:
    openvpn-2.6.12-1.amzn2023.0.7.src

x86_64:
    openvpn-debuginfo-2.6.12-1.amzn2023.0.7.x86_64
    openvpn-devel-2.6.12-1.amzn2023.0.7.x86_64
    openvpn-debugsource-2.6.12-1.amzn2023.0.7.x86_64
    openvpn-2.6.12-1.amzn2023.0.7.x86_64